IAM user permissions for iam:CreatePolicyVersion need review

Restrict the managed-policy versions that a user can create and activate.

Description

An IAM user can change attached identities’ permissions by creating a customer managed policy version with iam:CreatePolicyVersion and making it default. Strengthening a policy that applies directly to the user or through a group can enable privilege escalation.

A new version becomes operative only when it is made default. The creation request can do this, so restricting iam:SetDefaultPolicyVersion alone does not block this path.

Potential impact

  • Several users and roles sharing a policy can receive excessive permissions.
  • Changes under an existing policy name can alter the approved permission configuration.

Remediation

Remove unnecessary iam:CreatePolicyVersion from ordinary users and manage versions through approved roles. Restrict Resource to target customer managed policy ARNs and review iam:SetDefaultPolicyVersion too. Check policy contents and affected identities, and test that approved changes work and unapproved changes are blocked.

Examples

This grants managed-policy version creation through the same user’s inline policy. A separate policy attachment resource is not needed for the comparison.

Before

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:CreatePolicyVersion",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This grants the user permission to create versions across customer managed policies.

After

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This statement now contains only EC2 describe actions. Review version-management rights and describe scope in other policies.

References