IAM role with read access to production S3 data can be assumed by a third party

Description

An IAM role with read access to production S3 data can be assumed by a third party. This configuration allows an external AWS account to assume a role that has read permissions on production S3 buckets. The third party, or an attacker who compromises the third-party account, can assume this role and exfiltrate sensitive production data including personally identifiable information, credentials, financial records, or proprietary business data.

Remediation

  1. Review and manage IAM roles to ensure only trusted accounts can assume the role, and require external ID for third-party access.
  2. Apply IAM security best practices to follow the principle of least privilege and remove unnecessary S3 read permissions from third-party-assumable roles.