Description
Overly broad iam:AttachGroupPolicy permissions can let an IAM user attach powerful managed policies to groups and change members’ permissions. If the user can target a group they belong to, their own permissions can also expand.
The targets are IAM groups in the same account. Permission to attach group policies does not itself allow membership changes or administration of other AWS accounts.
Potential impact
- One user’s incorrect attachment can expand permissions for several group members.
- Unapproved powerful policies can increase the risk of resource access and modification.
Remediation
Remove unnecessary iam:AttachGroupPolicy permissions and use approved administrative roles. Where needed, specify target group ARNs in Resource and restrict attached policies with iam:PolicyARN conditions. Review membership and other permission limits, and test intended operations and denial of unapproved attachments.
Examples
This comparison keeps the same user and inline policy. A separate policy-attachment resource is not needed for this inline grant.
Before
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "test_inline_policy"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:AttachGroupPolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This permits the user to attach managed policies across groups.
After
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "test_inline_policy"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This replaces that grant with EC2 describe actions. Check whether other policies still grant the same attachment permission.