Federation lets an external identity provider mint AWS role credentials without an IAM user. The trust is declared by an IAM identity provider object plus a role whose trust policy accepts tokens from it, scoped by Condition on claims such as sub and aud. When those conditions are loose, an attacker who controls or can forge a matching token assumes the role.
What folds in here#
- SAML:
sts:AssumeRoleWithSAMLand over-broad SAML provider trust. - OIDC:
sts:AssumeRoleWithWebIdentityand weaksub/audconditions on an OIDC provider. - GitHub Actions: the GitHub OIDC provider with a
subcondition loose enough to accept other repositories or branches. - Trusted IdP: third-party IdPs (Auth0, Okta, Google) trusted as web-identity providers.
- Roles Anywhere: X.509 certificate trust that mints role credentials outside AWS.