Description
A bucket policy that grants Get actions to Principal: "*" can let unintended users, including anonymous users, read information. Effective access depends on the actions, resources, policy conditions, explicit denies and Block Public Access settings.
Potential impact
s3:GetObject permits reading object contents. Other Get actions can return bucket or object configuration, so the information at risk depends on the permitted action.
Remediation
Allow only the required read actions and resource ARNs, and restrict Principal to trusted identities such as specific roles. Enable Block Public Access where public access is unnecessary.
Examples
These examples show a policy change that limits object reading to one role. Replace the bucket name and role ARN with values from your environment. Block Public Access also affects whether a public policy can be applied.
Before
- name: Bucket
amazon.aws.s3_bucket:
name: mys3bucket
state: present
policy:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: s3:GetObject
Resource: "arn:aws:s3:::mys3bucket/*"
Principal: "*"
After
- name: Bucket
amazon.aws.s3_bucket:
name: mys3bucket
state: present
policy:
Version: "2012-10-17"
Statement:
- Effect: Allow
Action: s3:GetObject
Resource: "arn:aws:s3:::mys3bucket/*"
Principal:
AWS: "arn:aws:iam::123456789012:role/S3Reader"