IAM user has excessive glue:UpdateDevEndpoint permissions

Limit Glue development endpoint updates to the required targets.

Description

glue:UpdateDevEndpoint can modify a development endpoint’s public keys and libraries. A user who gains control of a reachable endpoint can run work with the permissions of its attached role.

Potential impact

  • A more powerful endpoint role can expand the user’s access.
  • A legitimate development environment can become a path for malicious code execution.

Remediation

Remove unnecessary glue:UpdateDevEndpoint permission. Limit required administration to approved development endpoints, give endpoint roles only the permissions they need, and review changes.

Examples

The examples change the same user’s inline policy to EC2 describe permissions. Choose permissions for the actual work and check other attached policies. This change does not restore an endpoint that has already been modified.

Before

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "glue:UpdateDevEndpoint",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

After

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "inline_policy_run_instances"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

References