Description
Without a control blocking public ACLs, an ACL mistake can grant unintended public permissions on an S3 bucket or object. BlockPublicAcls rejects requests containing new public ACLs; it does not remove existing ACLs.
Effective public access depends on whether ACLs are enabled and on other protections. New buckets have ACLs disabled by default, and IgnorePublicAcls or account-level blocks can also prevent public ACL permissions from taking effect.
Potential impact
- Effective public read permissions can expose object contents or listings.
- Effective public write permissions on a bucket can allow unwanted object creation or deletion.
Remediation
- If public ACLs are unnecessary, set
BlockPublicAcls: trueinPublicAccessBlockConfiguration. - Remove existing public ACL grants and enable
IgnorePublicAcls. For private buckets, also review the remaining Block Public Access settings and bucket policies. - Configure required access in policies before disabling ACLs.
Examples
These examples compare the setting that blocks new public ACLs.
Before
Resources:
Bucket1:
Type: AWS::S3::Bucket
Properties:
PublicAccessBlockConfiguration:
BlockPublicAcls: false
BlockPublicPolicy: true
IgnorePublicAcls: true
RestrictPublicBuckets: true
Although BlockPublicAcls is off, IgnorePublicAcls: true ignores public ACL permissions. This example alone does not establish that objects are public.
After
Resources:
Bucket1:
Type: AWS::S3::Bucket
Properties:
PublicAccessBlockConfiguration:
BlockPublicAcls: true
BlockPublicPolicy: true
IgnorePublicAcls: true
RestrictPublicBuckets: true
New public ACL requests are blocked, and existing public ACL permissions are ignored. Verify that required application access still works.