Wildcard principals in S3 object-read policies

Allowing S3 Get actions for all principals can expose object data or configuration information, depending on the action, resource and effective access controls.

Description

A bucket policy that grants Get actions to Principal: "*" can let unintended users, including anonymous users, read information. Effective access depends on the actions, resources, policy conditions, explicit denies and Block Public Access settings.

Potential impact

s3:GetObject permits reading object contents. Other Get actions can return bucket or object configuration, so the information at risk depends on the permitted action.

Remediation

Allow only the required read actions and resource ARNs, and restrict Principal to trusted identities such as specific roles. Enable Block Public Access where public access is unnecessary.

Examples

These examples show a policy change that limits object reading to one role. Replace the bucket name and role ARN with values from your environment. Block Public Access also affects whether a public policy can be applied.

Before

yaml
- name: Bucket
  amazon.aws.s3_bucket:
    name: mys3bucket
    state: present
    policy:
      Version: "2012-10-17"
      Statement:
        - Effect: Allow
          Action: s3:GetObject
          Resource: "arn:aws:s3:::mys3bucket/*"
          Principal: "*"

After

yaml
- name: Bucket
  amazon.aws.s3_bucket:
    name: mys3bucket
    state: present
    policy:
      Version: "2012-10-17"
      Statement:
        - Effect: Allow
          Action: s3:GetObject
          Resource: "arn:aws:s3:::mys3bucket/*"
          Principal:
            AWS: "arn:aws:iam::123456789012:role/S3Reader"

References