Description
An effective S3 bucket-policy grant to a wildcard principal can permit unwanted access, including anonymous requests. s3:GetObject permits reading object contents; other Get actions can retrieve bucket settings or particular object information. Read permission does not itself grant permission to modify or delete objects.
Actual access depends on actions, resources, conditions, explicit denies and Block Public Access. Even intentionally public data, such as website assets, should receive only the required read access.
Potential impact
- Effective object-read access can disclose documents, logs or backups.
- Other permitted read operations can reveal bucket configuration or object information.
Remediation
- Remove unnecessary public grants and give the relevant read permissions only to roles or services that need them.
- Use the required object ARNs for object operations and the bucket ARN for bucket operations, and review applicable conditions.
- Apply Block Public Access to private buckets and review other policies and ACLs. Test that intended reads succeed and unwanted reads are denied.
Examples
Supply the name of an existing bucket as BucketName. These examples use object ARNs. Account-level or bucket-level Block Public Access can reject a public policy; do not disable existing protections merely to apply the example.
Before
Parameters:
BucketName:
Type: String
Resources:
SampleBucketPolicy3:
Type: AWS::S3::BucketPolicy
Properties:
Bucket: !Ref BucketName
PolicyDocument:
Version: '2012-10-17'
Statement:
- Action: s3:GetObject
Effect: Allow
Resource: !Sub 'arn:${AWS::Partition}:s3:::${BucketName}/*'
Principal: '*'
This statement grants s3:GetObject on the bucket’s objects to every principal. Other access controls still determine whether public access is effective.
After
Parameters:
BucketName:
Type: String
Resources:
SampleBucketPolicy3:
Type: AWS::S3::BucketPolicy
Properties:
Bucket: !Ref BucketName
PolicyDocument:
Version: '2012-10-17'
Statement:
- Action:
- s3:GetObject
Effect: Deny
Resource: !Sub 'arn:${AWS::Partition}:s3:::${BucketName}/*'
Principal: '*'
This explicit deny can also block s3:GetObject for legitimate users. If some users need reads, remove the public grant and grant only the required permissions instead of applying this blanket deny unchanged.