Description
In an S3 bucket policy, Principal: "*" does not restrict the principal to a specific user or role. Using it in a deletion grant without suitable access restrictions can allow principals that do not need deletion permissions to remove data or settings.
Effective permissions depend on the allowed actions, target Resource, Condition, explicit denies, and S3 Block Public Access settings. Deleting objects and deleting bucket settings are separate operations, so review the permissions needed for each.
Potential impact
- If effective policy evaluation allows principals that do not need deletion permission to delete objects, data loss or service disruption can result.
- Deleting logs or backups, or hiding them from ordinary retrieval, can hinder investigation and recovery. In a versioning-enabled bucket, a deletion without a version ID normally creates a delete marker; permanently deleting a specific version requires
s3:DeleteObjectVersionpermission. - Permission to delete bucket settings can also affect operations or protections that depend on those settings.
Remediation
- Remove unnecessary deletion grants. Grant required deletion permissions only to specific operational roles or accounts.
- Use valid action names and precise bucket or object ARNs to limit scope. Review conditions, other allow and deny policies, and Block Public Access together.
- Configure versioning and backups according to recovery needs and test recovery procedures. Versioning does not replace restrictions on deletion permissions.
Examples
These excerpts compare an allow statement with an explicit deny. The referenced DOC-EXAMPLE-BUCKET definition is omitted, and a deployment needs bucket or object ARNs appropriate to the actions.
Incomplete deletion grant
Resources:
SampleBucketPolicy3:
Type: "AWS::S3::BucketPolicy"
Properties:
Bucket: !Ref DOC-EXAMPLE-BUCKET
PolicyDocument:
Statement:
- Action: "DeleteObject"
Effect: Allow
Resource: "*"
Principal: "*"
This statement intends to allow deletion by every principal, but DeleteObject lacks the required s3: prefix and is not a valid AWS policy action. Correcting the action name alone is insufficient: restrict the principals and target resources to those required.
Explicit denial of object deletion
Resources:
SampleBucketPolicy1:
Type: "AWS::S3::BucketPolicy"
Properties:
Bucket: !Ref DOC-EXAMPLE-BUCKET
PolicyDocument:
Statement:
- Action:
- "s3:DeleteObject"
Effect: Deny
Resource: "*"
Principal: "*"
In a valid policy, Effect: Deny explicitly denies s3:DeleteObject on the specified resources to every principal, which can also disrupt legitimate operations. This statement does not deny other actions such as s3:DeleteObjectVersion. Check required operational actions and recovery procedures before applying it.