Description
An allow statement with Principal set to * can grant S3 access to a broad set of principals, including anonymous requests. Effective permissions depend on the allowed actions and resources, policy conditions, explicit denies, and Block Public Access settings. If the principal scope is missing, make the intended scope explicit and validate the policy. Omission does not itself grant access.
Potential impact
- Unintended principals with object-read permission can obtain data. If writes or deletions are also allowed, they can alter or remove data.
- Relaxing conditions or settings that currently block public access can expose the broad permissions in the policy.
Remediation
- Specify the required accounts, roles, users, or services and limit their actions and resources. Correct missing or invalid policy elements and validate the complete policy.
- Apply Block Public Access to internal buckets and check the effective account and bucket settings. For intentionally public data, allow only the required operations on the intended resources and review the conditions.
- Ensure the policy's resource ARNs identify the bucket you will deploy. Review the policy with tools such as IAM Access Analyzer and verify that required access works while unnecessary access is denied.
Examples
The example bucket has no BucketName, but the policy uses object ARNs for the fixed name DOC-EXAMPLE-BUCKET. Replace these with the actual bucket's object ARNs and existing IAM principals, and check Block Public Access settings.
Before
Resources:
Bucket:
Type: AWS::S3::Bucket
BucketPolicy:
Type: AWS::S3::BucketPolicy
Properties:
Bucket: !Ref Bucket
PolicyDocument:
Statement:
- Effect: Allow
Principal:
AWS:
- "*"
Action: s3:GetObject
Resource: arn:aws:s3:::DOC-EXAMPLE-BUCKET/*
After
Resources:
Bucket:
Type: AWS::S3::Bucket
BucketPolicy:
Type: AWS::S3::BucketPolicy
Properties:
Bucket: !Ref Bucket
PolicyDocument:
Statement:
- Effect: Allow
Principal:
AWS:
- arn:aws:iam::111122223333:user/Alice
- arn:aws:iam::111122223333:user/foo
Action: s3:GetObject
Resource: arn:aws:s3:::DOC-EXAMPLE-BUCKET/*
Explanation:
- Before: The statement allows
s3:GetObjectfor all principals. It can make the specified objects public unless other access controls block access; it does not grant writes or deletions. - After: The same read operation is limited to two user ARNs. This statement does not restrict permissions those users receive from other policies, so review their overall access.