T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:43- Finding
Excessive Subscription-Wide Azure RBAC Recommendation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 43-50
Vulnerability Type: Least-privilege violation through excessive Azure RBAC guidance
Risk Level: HighComplete Code Snippet:
markdown **Minimum required Azure RBAC role to run the CLI commands above (read-only):** ```json { "role": "Storage Account Contributor", "scope": "Subscription", "note": "Use 'Reader' role at minimum for account-level config; 'Storage Blob Data Reader' to list containers" }text ### Technical Analysis The Skill identifies `Storage Account Contributor` at subscription scope as the minimum role required for read-only Azure Storage inspection. This is inaccurate and violates least-privilege principles. `Storage Account Contributor` is a management-plane role that can modify storage accounts; it is not limited to reading their configuration. Assigning it at subscription scope grants unnecessary management privileges over storage accounts throughout the subscription. The recommendation conflicts with both the Skill's `permissions: read-only` declaration and its own note that `Reader` can inspect account-level configuration. The listed `az storage account list` and `az storage account show` operations generally require management-plane read access, for which `Reader` at the narrowest applicable scope is appropriate. Container enumeration may separately require data-plane access such as `Storage Blob Data Reader`, scoped only to the relevant storage account or container. Authentication should explicitly use Microsoft Entra ID rather than account-key fallback. ### Attack Path 1. A user follows the Skill's claim that `Storage Account Contributor` at subscription scope is the minimum prerequisite. 2. The user assigns that role to a person, service principal, managed identity, or automation identity performing the audit. 3. That identity obtains write-capable storage-management privileges across the subscript ...[truncated 959 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the claim that
Storage Account Contributoris the minimum required role. - Recommend the Azure
Readerrole for management-plane configuration inspection. - Scope
Readerto the specific resource group or storage account whenever possible, rather than the entire subscription. - Where container enumeration requires data-plane access, assign
Storage Blob Data Readeronly to the relevant storage account or container. - Separate management-plane and data-plane prerequisites so users do not infer that one broad contributor role is required.
- Require Microsoft Entra ID authentication for data-plane commands, for example by documenting
--auth-mode login, to avoid implicit account-key authentication. - Advise users to use a temporary audit identity or time-bound privileged-access workflow and remove assignments after the audit.
- Document the exact Azure operations needed and, where built-in roles remain broader than necessary, provide a reviewed custom read-only role containing only those operations.
- Add a warning that contributor roles must not be assigned for this read-only workflow.
A safer prerequisite would distinguish the roles as follows:
markdown - Account configuration inspection: Azure `Reader`, scoped to the smallest applicable storage account or resource group. - Container enumeration: `Storage Blob Data Reader`, scoped only to the storage account or container being assessed. - Use Microsoft Entra ID authentication (`--auth-mode login`); do not provide or request storage account keys.- Remove the claim that
