Review S3 public ACL blocking

Review the S3 control that rejects new public ACLs and remove existing public grants.

Description

Without a control blocking public ACLs, an ACL mistake can grant unintended public permissions on an S3 bucket or object. BlockPublicAcls rejects requests containing new public ACLs; it does not remove existing ACLs.

Effective public access depends on whether ACLs are enabled and on other protections. New buckets have ACLs disabled by default, and IgnorePublicAcls or account-level blocks can also prevent public ACL permissions from taking effect.

Potential impact

  • Effective public read permissions can expose object contents or listings.
  • Effective public write permissions on a bucket can allow unwanted object creation or deletion.

Remediation

  • If public ACLs are unnecessary, set BlockPublicAcls: true in PublicAccessBlockConfiguration.
  • Remove existing public ACL grants and enable IgnorePublicAcls. For private buckets, also review the remaining Block Public Access settings and bucket policies.
  • Configure required access in policies before disabling ACLs.

Examples

These examples compare the setting that blocks new public ACLs.

Before

yaml
Resources:
  Bucket1:
    Type: AWS::S3::Bucket
    Properties:
      PublicAccessBlockConfiguration:
        BlockPublicAcls: false
        BlockPublicPolicy: true
        IgnorePublicAcls: true
        RestrictPublicBuckets: true

Although BlockPublicAcls is off, IgnorePublicAcls: true ignores public ACL permissions. This example alone does not establish that objects are public.

After

yaml
Resources:
  Bucket1:
    Type: AWS::S3::Bucket
    Properties:
      PublicAccessBlockConfiguration:
        BlockPublicAcls: true
        BlockPublicPolicy: true
        IgnorePublicAcls: true
        RestrictPublicBuckets: true

New public ACL requests are blocked, and existing public ACL permissions are ignored. Verify that required application access still works.

References