Granting an IAM user permissions to both cloudformation:CreateStack and iam:PassRole with "Resource": "*" is a significant security risk, as it allows the user to create CloudFormation stacks that assume any IAM role in the AWS account. This creates a privilege escalation vector, enabling the user to gain broader or even administrative privileges, bypassing intended access controls. If left unaddressed, an attacker or insider with these rights could compromise the integrity and confidentiality of AWS resources, leading to unauthorized access or manipulation of critical infrastructure.
resource"aws_iam_user""cosmic"{name="cosmic"}resource"aws_iam_user_policy""test_inline_policy"{name="test_inline_policy"user=aws_iam_user.cosmic.namepolicy= jsonencode({Version="2012-10-17"Statement=[{Action=["cloudformation:CreateStack",]Effect="Allow"Resource="*"},]})}resource"aws_iam_policy_attachment""test-attach"{name="test-attachment"users=[aws_iam_user.cosmic.name]roles=[aws_iam_role.role.name]groups=[aws_iam_group.group.name]policy_arn=aws_iam_policy.policy.arn}resource"aws_iam_policy""policy"{name="test-policy"description="A test policy"policy= jsonencode({Version="2012-10-17"Statement=[{Action=["iam:PassRole",]Effect="Allow"Resource="*"},]})}
1
2
rulesets:- Terraform / AWS # Rules to enforce / AWS.
맞춤형 데모 요청
Datadog 시작하기
Ask AI
AI-generated responses may be inaccurate. Verify important info.