Public-read ACLs in S3

Check that public-read ACLs do not share object listings or object contents beyond the intended audience.

Description

A public-read ACL grants READ to everyone, including anonymous requests, in addition to the owner's permissions. On a bucket, READ permits listing the objects in that bucket. On an object, it permits reading that object's content and metadata. A bucket ACL alone does not make every object's content readable.

Effective permissions also depend on Object Ownership, Block Public Access and policies. When BucketOwnerEnforced disables ACLs, ACLs no longer participate in authorization and requests to set an ACL can be rejected.

Potential impact

  • Effective public-read access can expose object names or object contents that were not intended for the public.
  • public-read-write also grants permission to create objects in the bucket. Overwriting or deleting existing objects remains subject to bucket and object ownership restrictions, but unwanted uploads can still create costs and operational problems.

Remediation

  • Remove public ACL grants from buckets and objects that do not need them. Use policies to authorize only the accounts and roles that require access.
  • Move required ACL permissions into policies, then disable ACLs where possible and apply Block Public Access. Check existing access paths first to avoid interrupting legitimate use.
  • Inspect actual bucket and object ACLs and policies. Verify that required access continues and unwanted access is denied. Changing a bucket ACL alone does not remove permissions granted by object ACLs or separate policies.

Examples

These examples use the current bucket-management module. Set bucket_name to the bucket you manage. Both assume an existing bucket with ACLs enabled; Block Public Access can reject or ignore public ACLs. Do not weaken existing protections to apply the first example.

Before

yaml
- name: Set a bucket ACL
  amazon.aws.s3_bucket:
    name: "{{ bucket_name }}"
    state: present
    acl: public-read

If effective, this ACL lets anonymous users list objects in the bucket. Check read permissions on individual objects separately.

After

yaml
- name: Set a bucket ACL
  amazon.aws.s3_bucket:
    name: "{{ bucket_name }}"
    state: present
    acl: private

This removes public ACL grants and grants ACL permissions only to the owner. Other policies can still allow access, so review the complete permissions. A bucket with ACLs already disabled does not need an ACL update.

References