Description
Broad iam:PutUserPolicy permissions let an IAM user add or replace inline policies on themselves or other users. Granting stronger permissions to a target user can enable privilege escalation where other limits do not block the resulting access.
Policy changes do not automatically remove permissions boundaries, organization policies or explicit denies. Review the actual users and other policies together.
Potential impact
- Users can increase their own resource access or modification rights without approval.
- Excessive grants to other users can increase the impact of credential misuse.
Remediation
Remove unnecessary iam:PutUserPolicy from ordinary users and perform administration through approved roles. Where needed, restrict Resource to target user ARNs. Review self-modification paths and change logs, and verify that intended work succeeds and unapproved changes are blocked.
Examples
This comparison changes only the allowed actions in the same user and inline policy.
Before
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "test_inline_policy"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:PutUserPolicy",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This grants the user permission to add or update inline policies across users, including themselves.
After
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "test_inline_policy"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
This statement now contains only EC2 describe actions. Also review user-policy modification permissions and unnecessary describe access in other policies.