S3 ACL grants read access to every AWS account

An authenticated-read ACL does not limit access to the owner's account. Check whether read access by every AWS account is necessary.

Description

The authenticated-read ACL gives the owner full ACL permissions and grants READ to the AuthenticatedUsers group. This group covers all AWS accounts making signed requests, not just users in the owner's account or organization. It differs from anonymous access through public-read, but it is not an internal-user-only setting.

Bucket READ permits listing objects in the bucket; object READ permits reading that object's contents and metadata. Effective permissions also depend on Object Ownership, Block Public Access and policies. ACLs do not grant access on a bucket where they are disabled.

Potential impact

  • If the bucket ACL is effective, other AWS accounts that do not need listing access may see object names and listing information.
  • If the object ACL is effective, that object's contents and metadata may be shared beyond the intended accounts. An authenticated request does not by itself identify a trusted user.

Remediation

  • Remove authenticated-read grants from buckets and objects that do not need read access by every AWS account. Authorize the required accounts and roles explicitly in policies.
  • Move legitimate access that depends on ACLs into policies, then disable ACLs where possible and apply Block Public Access.
  • Inspect actual bucket and object ACLs and policies. Verify that required access continues and unwanted accounts are denied. Changing the bucket ACL alone does not remove permissions from object ACLs or other policies.

Examples

These examples use the current bucket-management module. Set bucket_name to the bucket you manage. They assume an existing bucket with ACLs enabled. Block Public Access can reject or ignore the first ACL; do not weaken protections to apply the example.

Listing access for every AWS account

yaml
- name: Set a bucket ACL
  amazon.aws.s3_bucket:
    name: "{{ bucket_name }}"
    state: present
    acl: authenticated-read

If effective, this ACL allows all AWS accounts making signed requests to list objects in the bucket. It does not grant read access to every object's contents through the bucket ACL.

Owner-only ACL

yaml
- name: Set a bucket ACL
  amazon.aws.s3_bucket:
    name: "{{ bucket_name }}"
    state: present
    acl: private

Only the owner receives ACL permissions. Access granted through policies can remain. If ACLs are already disabled, manage policies and effective access rather than attempting to set an ACL again.

References