IAM user permissions for iam:AttachRolePolicy need review

Restrict a user’s role-policy attachments to approved roles and policies.

Description

An IAM user can expand a role’s permissions by attaching a powerful managed policy with iam:AttachRolePolicy. The user can use those expanded permissions if they can assume the role or control a workload running with it.

Attachment alone changes neither the user’s own permissions nor the role’s trust. Boundaries, organization policies and explicit denies can also limit actual access.

Potential impact

  • Applications using a role can gain resource access they do not need.
  • Unapproved policy changes can alter service permissions and operational controls.

Remediation

Remove unnecessary iam:AttachRolePolicy and use approved roles for required administration. Restrict Resource to target role ARNs and specify allowed policies with iam:PolicyARN conditions. Review role-use paths and other permissions, and test intended operations and denial of unapproved attachments.

Examples

This changes the same user and inline policy. A separate managed-policy attachment resource is not needed for the comparison.

Before

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:AttachRolePolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This permits the user to attach managed policies across roles.

After

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grant now contains only EC2 describe actions. Restrict role-administration grants in other policies and describe access to the workload’s needs.

References