iam_role_cross_service_confused_deputy_prevention remediation broke specific process #4714
Labels
bug
provider/aws
Issues/PRs related with the AWS provider
severity/medium
Results in some unexpected or undesired behavior.
Steps to Reproduce
Expected behavior
Prowler recommends to remediate/prevent confused deputy its either use aws:SourceArn or aws:SourceAccount or both. If the specfici resource has been added in the condition nothing should break our process.
Actual Result with Screenshots or Logs
Prowlers solution works on some roles but for cloudtrail to cloudwatch process that a role will handle it breaks. We also encounter in IAM role that's assumed by aws transcoder when we add either aws:SourceArn or aws:SourceAccount or both. Our process will stop working.
The exact trust relationship policy for the transcoder role:
{
"Version": "2008-10-17",
"Statement": [
{
"Sid": "1",
"Effect": "Allow",
"Principal": {
"Service": [
"elastictranscoder.amazonaws.com",
"transcribe.amazonaws.com"
]
},
"Action": "sts:AssumeRole",
"Condition": {
"StringEquals": {
"aws:SourceAccount": "<account_id>"
},
"ArnLike": {
"aws:SourceArn": [
"arn:aws:elastictranscoder::<account_id>:pipeline/example_pipeline",
"arn:aws:elastictranscoder::<account_id>:job/",
"arn:aws:elastictranscoder::<account_id>:preset/"
]
}
}
}
]
}
How did you install Prowler?
From pip package (pip install prowler)
Environment Resource
Workstation
OS used
Windows
Prowler version
4.2.4
Pip version
pip 23.2.1
Context
We consulted the cloudtrail to cloudwatch process role to AWS Support and they mention "no documentation around which services do or do not support the aws:SourceArn or aws:SourceAccount condition keys because they're global condition keys and technically available to all services. The keys are supported in any situation where a service tries to access another service's resource with a call from their service principal. If it's not from a service principal, we don't expect those condition keys to be set."
The text was updated successfully, but these errors were encountered: