logo

Database

Aws Group Permissive Inline Policies

Description

Detects AWS IAM groups that have inline policies with overly permissive permissions. Inline policies attached directly to IAM groups that grant broad or unrestricted access create security risks by potentially allowing excessive privileges to group members.

Weakness:

325 - Excessive privileges - Wildcards

Category: Access Subversion

Detection Strategy

    Scans all IAM groups in the AWS account for inline policies

    Triggers when an inline policy attached to a group contains overly permissive statements like '*' in actions or resources

    Examines each inline policy document for dangerous permissions that grant broad access across AWS services

    Reports vulnerabilities at the individual policy level, identifying which group and policy contains excessive permissions

Severity v4.0

0.5

Low

Method ID

CSPM-AIW3E

Technique

CSPM

Target

AWS

Technology

IAM

CWE ID(s)

CWE-250