S3 Get permissions for a wildcard principal

Limit S3 read permissions to the intended principals and resources.

Description

An effective S3 bucket-policy grant to a wildcard principal can permit unwanted access, including anonymous requests. s3:GetObject permits reading object contents; other Get actions can retrieve bucket settings or particular object information. Read permission does not itself grant permission to modify or delete objects.

Actual access depends on actions, resources, conditions, explicit denies and Block Public Access. Even intentionally public data, such as website assets, should receive only the required read access.

Potential impact

  • Effective object-read access can disclose documents, logs or backups.
  • Other permitted read operations can reveal bucket configuration or object information.

Remediation

  • Remove unnecessary public grants and give the relevant read permissions only to roles or services that need them.
  • Use the required object ARNs for object operations and the bucket ARN for bucket operations, and review applicable conditions.
  • Apply Block Public Access to private buckets and review other policies and ACLs. Test that intended reads succeed and unwanted reads are denied.

Examples

Supply the name of an existing bucket as BucketName. These examples use object ARNs. Account-level or bucket-level Block Public Access can reject a public policy; do not disable existing protections merely to apply the example.

Before

yaml
Parameters:
  BucketName:
    Type: String
Resources:
  SampleBucketPolicy3:
    Type: AWS::S3::BucketPolicy
    Properties:
      Bucket: !Ref BucketName
      PolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Action: s3:GetObject
            Effect: Allow
            Resource: !Sub 'arn:${AWS::Partition}:s3:::${BucketName}/*'
            Principal: '*'

This statement grants s3:GetObject on the bucket’s objects to every principal. Other access controls still determine whether public access is effective.

After

yaml
Parameters:
  BucketName:
    Type: String
Resources:
  SampleBucketPolicy3:
    Type: AWS::S3::BucketPolicy
    Properties:
      Bucket: !Ref BucketName
      PolicyDocument:
        Version: '2012-10-17'
        Statement:
          - Action:
              - s3:GetObject
            Effect: Deny
            Resource: !Sub 'arn:${AWS::Partition}:s3:::${BucketName}/*'
            Principal: '*'

This explicit deny can also block s3:GetObject for legitimate users. If some users need reads, remove the public grant and grant only the required permissions instead of applying this blanket deny unchanged.

References