Description
Broad lambda:UpdateFunctionCode permission allows arbitrary changes to existing Lambda function code. When the changed code runs, it can access data and perform AWS operations with the function’s execution-role permissions, creating a potential indirect escalation path.
Permission to change code does not itself grant invocation permission. Review the actual execution path, versions and aliases in use, and the execution role’s permissions.
Potential impact
- Changed code, once executed, can expose or alter data accessible to the execution role.
- Function behavior can be altered or service operations disrupted.
Remediation
- Remove
lambda:UpdateFunctionCodefrom roles that do not need it, and restrict access to approved CI/CD roles and target function ARNs. - Keep execution roles least privileged and require review and approval for sensitive code deployments.
- Monitor code changes and verify that executed versions and aliases point to approved deployments.
Examples
These are role-permission excerpts. Configure the omitted, required assume_role_policy separately to trust only approved principals.
Before
hcl
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "test_inline_policy"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"lambda:UpdateFunctionCode",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
After
hcl
resource "aws_iam_role" "example" {
name = "cosmic"
}
resource "aws_iam_role_policy" "example" {
name = "inline_policy_run_instances"
role = aws_iam_role.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
Explanation:
- Before: Allows code changes without restricting the target functions. Impact depends on execution of the changed code and the execution role’s permissions.
- After: Limits the example policy on the same role to EC2 queries. Remove code-changing access from other policies too, and allow only required
ec2:Describe*queries.