Description
lambda:UpdateFunctionCode permits changing an existing Lambda function’s code. When the modified code executes, it uses the function’s execution-role permissions, so a powerful role can provide access beyond the user’s intended scope.
Potential impact
- Malicious code can alter the function’s normal business behavior.
- Access to secrets or data allowed for the execution role may be misused.
Remediation
Remove unnecessary lambda:UpdateFunctionCode permission. Limit required changes to approved functions and deployment procedures, minimize execution-role permissions, and review code changes.
Examples
The second inline policy allows the same user only EC2 describe operations. Check other attached policies too. Removing code-update permission does not restore code already deployed.
Before
hcl
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "test_inline_policy"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"lambda:UpdateFunctionCode",
]
Effect = "Allow"
Resource = "*"
},
]
})
}
After
hcl
resource "aws_iam_user" "example" {
name = "cosmic"
}
resource "aws_iam_user_policy" "example" {
name = "inline_policy_read_only"
user = aws_iam_user.example.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Action = [
"ec2:Describe*",
]
Effect = "Allow"
Resource = "*"
},
]
})
}