Description
An IAM user can expand a role’s permissions by attaching a powerful managed policy with iam:AttachRolePolicy. The user can use those expanded permissions if they can assume the role or control a workload running with it.
Attachment alone changes neither the user’s own permissions nor the role’s trust. Boundaries, organization policies and explicit denies can also limit actual access.
Potential impact
- Applications using a role can gain resource access they do not need.
- Unapproved policy changes can alter service permissions and operational controls.
Remediation
Remove unnecessary iam:AttachRolePolicy and use approved roles for required administration. Restrict Resource to target role ARNs and specify allowed policies with iam:PolicyARN conditions. Review role-use paths and other permissions, and test intended operations and denial of unapproved attachments.
Examples
This changes the same user and inline policy. A separate managed-policy attachment resource is not needed for the comparison.
Before
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "test_inline_policy"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:AttachRolePolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This permits the user to attach managed policies across roles.
After
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "test_inline_policy"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This grant now contains only EC2 describe actions. Restrict role-administration grants in other policies and describe access to the workload’s needs.