Description
Broad iam:CreateAccessKey permission can allow the creation of new access keys for other IAM users and their use for API access. If a target user has stronger permissions, this can lead to privilege escalation.
Potential impact
- New long-term keys can provide access to the target user’s data and services.
- Unnecessary keys can preserve an access path after the original permissions are changed.
Remediation
Remove unnecessary iam:CreateAccessKey permission and limit required key administration to approved target users. Prefer temporary credentials where possible, and review key-creation events and existing long-term keys.
Examples
The second inline policy grants the same user only EC2 describe permissions. Check other policies for key-creation permissions and separately deactivate or delete keys already issued.
Before
hcl
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "test_inline_policy"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:CreateAccessKey",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
After
hcl
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "inline_policy_read_only"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}