3 ms·
If the policy has AssumeRole with principal "AWS:*" then yes, anyone can assume it and get temporary credentials to resources. Normally you would put an account
by some_account 8y ago
If the policy has AssumeRole with principal "AWS:*" then yes, anyone can assume it and get temporary credentials to resources. Normally you would put an account number there but what if you want all your accounts to be able to assume the role and want a quick solution? I think a lot of people didn't realize that anyone on AWS can assume the role if they do this.
I think it's quite common for people to just put something in the policy that works on order to quickly proceed with whatever they are doing. Article says they found about 50 policies like this.