S3 bucket policy has a wildcard or missing principal

An S3 bucket policy with a wildcard principal can allow unintended access. Restrict principals, actions, resources, and policy conditions to the access you need.

Description

An allow statement with Principal set to * can grant S3 access to a broad set of principals, including anonymous requests. Effective permissions depend on the allowed actions and resources, policy conditions, explicit denies, and Block Public Access settings. If the principal scope is missing, make the intended scope explicit and validate the policy. Omission does not itself grant access.

Potential impact

  • Unintended principals with object-read permission can obtain data. If writes or deletions are also allowed, they can alter or remove data.
  • Relaxing conditions or settings that currently block public access can expose the broad permissions in the policy.

Remediation

  • Specify the required accounts, roles, users, or services and limit their actions and resources. Correct missing or invalid policy elements and validate the complete policy.
  • Apply Block Public Access to internal buckets and check the effective account and bucket settings. For intentionally public data, allow only the required operations on the intended resources and review the conditions.
  • Ensure the policy's resource ARNs identify the bucket you will deploy. Review the policy with tools such as IAM Access Analyzer and verify that required access works while unnecessary access is denied.

Examples

The example bucket has no BucketName, but the policy uses object ARNs for the fixed name DOC-EXAMPLE-BUCKET. Replace these with the actual bucket's object ARNs and existing IAM principals, and check Block Public Access settings.

Before

yaml
Resources:
  Bucket:
    Type: AWS::S3::Bucket
  BucketPolicy:
    Type: AWS::S3::BucketPolicy
    Properties:
      Bucket: !Ref Bucket
      PolicyDocument:
        Statement:
          - Effect: Allow
            Principal:
              AWS:
                - "*"
            Action: s3:GetObject
            Resource: arn:aws:s3:::DOC-EXAMPLE-BUCKET/*

After

yaml
Resources:
  Bucket:
    Type: AWS::S3::Bucket
  BucketPolicy:
    Type: AWS::S3::BucketPolicy
    Properties:
      Bucket: !Ref Bucket
      PolicyDocument:
        Statement:
          - Effect: Allow
            Principal:
              AWS:
                - arn:aws:iam::111122223333:user/Alice
                - arn:aws:iam::111122223333:user/foo
            Action: s3:GetObject
            Resource: arn:aws:s3:::DOC-EXAMPLE-BUCKET/*

Explanation:

  • Before: The statement allows s3:GetObject for all principals. It can make the specified objects public unless other access controls block access; it does not grant writes or deletions.
  • After: The same read operation is limited to two user ARNs. This statement does not restrict permissions those users receive from other policies, so review their overall access.

References