Description
Allowing Put actions for Principal: "*" in a bucket policy can let unintended callers write objects or change settings. The operations actually permitted depend on the specified actions and resources, conditions, explicit denies, and Block Public Access settings.
Not every Put action uploads an object. s3:PutObject writes objects, while other actions can change separate settings, so review the permissions needed for each operation.
Potential impact
- If principals that do not need to write objects effectively have
s3:PutObjectpermission, they can create objects or change the current contents at an existing key. Versioning, conditional requests, and other settings also affect the outcome. - Changes to objects used by an application can affect its content or processing results. Assess other Put actions according to the resources and settings they change.
- Unnecessary uploads can increase storage and request costs. Put permissions alone do not also grant reading or deletion.
Remediation
- Identify the exact operations required, and grant write or configuration-change permissions only to the necessary principals and resource ARNs.
- Determine effective access from the full policy, including conditions, explicit denies, and Block Public Access.
- Where object uploads are required, also review how consuming services validate uploaded data and manage storage costs.
Examples
These historical examples cannot be deployed as written. Version: "2020-10-07" is an unsupported policy-language version, PutObject lacks the service prefix, and Resource is missing. For a real policy, specify a supported version, an exact action such as s3:PutObject, and the correct target ARN.
Before
- name: Bucket
amazon.aws.s3_bucket:
name: mys3bucket
state: present
policy:
Version: "2020-10-07"
Statement:
- Effect: Allow
Action: PutObject
Principal: "*"
After
- name: Bucket
amazon.aws.s3_bucket:
name: mys3bucket
state: present
policy:
Version: "2020-10-07"
Statement:
- Effect: Allow
Action: PutObject
Principal:
AWS: "arn:aws:iam::123456789012:role/upload-service-role"
Explanation:
- First example:
Principal: "*"does not limit who can write objects. When correcting the policy format, also restrict the principals and object scope. - Second example: A role responsible for uploads is specified. Correct the policy format, use the real role and target object ARNs, and verify that required uploads succeed while unwanted writes are denied.