IAM user permissions for iam:PutRolePolicy need review

Limit a user’s role inline-policy modifications to required targets.

Description

An IAM user can add or replace role inline policies with iam:PutRolePolicy, expanding permissions for services and sessions using the role. The user may misuse the expanded permissions if they can assume the role or control a workload using it.

Policy editing is separate from changing the role’s trust policy or obtaining permission to use it. Boundaries, organization policies and explicit denies can also limit actual actions.

Potential impact

  • Application roles can gain access to more resources than needed.
  • One role change can affect permissions for several service instances.

Remediation

Remove unnecessary iam:PutRolePolicy from ordinary users. Perform required changes through approved deployment or administration roles and restrict Resource to target role ARNs. Review policy contents and role-use paths, and verify that intended work succeeds and unapproved changes are blocked.

Examples

This comparison retains the same user and inline policy. A separate managed-policy attachment resource is unnecessary.

Before

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:PutRolePolicy",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This lets the user add or update inline policies across roles.

After

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

This statement now contains only EC2 describe actions. Also review modification rights and unnecessary describe access in other policies.

References