Description
Broad iam:UpdateLoginProfile permission can allow another IAM user’s console password to be changed. If the target is privileged and other sign-in controls permit access, its account can provide stronger permissions. Password-changing permission does not itself disable MFA.
Potential impact
- A password change can disrupt the legitimate user’s console access.
- A principal that successfully signs in can perform operations allowed for the target user.
Remediation
Remove iam:UpdateLoginProfile permission from users who do not administer passwords. Limit required administration to approved target users, and review password changes and sign-in controls such as MFA.
Examples
The second policy grants the same user only EC2 describe permissions. Remove or restrict password-changing permissions in other policies, and separately check passwords and account state that have already changed.
Before
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "test_inline_policy"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"iam:UpdateLoginProfile",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
After
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "inline_policy_read_only"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}