Ce produit n'est pas pris en charge par le site Datadog que vous avez sélectionné. ().
Cette page n'est pas encore disponible en français, sa traduction est en cours. Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.
Granting an IAM user iam:UpdateAssumeRolePolicy and sts:AssumeRole permissions with the resource set to "*" allows them to escalate their privileges by modifying the trust policies of IAM roles and then assuming those roles. This configuration effectively enables the user to grant themselves access to any role and associated permissions in the AWS account, bypassing intended security controls. If left unaddressed, this vulnerability could lead to full account compromise, data exfiltration, or malicious activity performed under elevated permissions.
resource"aws_iam_user""cosmic"{name="cosmic"}resource"aws_iam_user_policy""test_inline_policy"{name="test_inline_policy"user=aws_iam_user.cosmic.namepolicy= jsonencode({Version="2012-10-17"Statement=[{Action=["iam:UpdateAssumeRolePolicy",]Effect="Allow"Resource="*"},]})}resource"aws_iam_policy_attachment""test-attach"{name="test-attachment"users=[aws_iam_user.cosmic.name]roles=[aws_iam_role.role.name]groups=[aws_iam_group.group.name]policy_arn=aws_iam_policy.policy.arn}resource"aws_iam_policy""policy"{name="test-policy"description="A test policy"policy= jsonencode({Version="2012-10-17"Statement=[{Action=["sts:AssumeRole",]Effect="Allow"Resource="*"},]})}
1
2
rulesets:- Terraform / AWS # Rules to enforce / AWS.
Request a personalized demo
Commencer avec Datadog
Ask AI
AI-generated responses may be inaccurate. Verify important info.