Description
An IAM user can add or replace role inline policies with iam:PutRolePolicy, expanding permissions for services and sessions using the role. The user may misuse the expanded permissions if they can assume the role or control a workload using it.
Policy editing is separate from changing the role’s trust policy or obtaining permission to use it. Boundaries, organization policies and explicit denies can also limit actual actions.
Potential impact
- Application roles can gain access to more resources than needed.
- One role change can affect permissions for several service instances.
Remediation
Remove unnecessary iam:PutRolePolicy from ordinary users. Perform required changes through approved deployment or administration roles and restrict Resource to target role ARNs. Review policy contents and role-use paths, and verify that intended work succeeds and unapproved changes are blocked.
Examples
This comparison retains the same user and inline policy. A separate managed-policy attachment resource is unnecessary.
Before
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "test_inline_policy"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:PutRolePolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This lets the user add or update inline policies across roles.
After
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "test_inline_policy"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This statement now contains only EC2 describe actions. Also review modification rights and unnecessary describe access in other policies.