Description
glue:UpdateDevEndpoint can modify a development endpoint’s public keys and libraries. A user who gains control of a reachable endpoint can run work with the permissions of its attached role.
Potential impact
- A more powerful endpoint role can expand the user’s access.
- A legitimate development environment can become a path for malicious code execution.
Remediation
Remove unnecessary glue:UpdateDevEndpoint permission. Limit required administration to approved development endpoints, give endpoint roles only the permissions they need, and review changes.
Examples
The examples change the same user’s inline policy to EC2 describe permissions. Choose permissions for the actual work and check other attached policies. This change does not restore an endpoint that has already been modified.
Before
hcl
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "test_inline_policy"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"glue:UpdateDevEndpoint",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
After
hcl
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "inline_policy_run_instances"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}