Description
An S3 bucket policy that grants write operations to Principal: "*" can let untrusted principals store data or change settings if suitable access restrictions are absent. Grant these permissions only to services or operational roles that need them.
s3:PutObject permits object uploads, while other Put actions can change bucket or object settings. Effective access depends on the actions, target resources, conditions, explicit denies, and S3 Block Public Access settings. Review upload permissions separately from administrative permissions.
Potential impact
- If
s3:PutObjectis effectively granted more broadly than necessary, principals that do not need upload permission can add objects or write new contents under an existing key. With versioning enabled, an upload to the same key creates a new version and retains previous versions. - Web services or data processing systems that consume these objects may serve or process unintended content. If configuration operations are allowed, assess the consequences of those specific operations separately.
- Unnecessary uploads, when permitted, can increase storage costs and processing load.
Remediation
- Remove unnecessary public write grants and allow required operations only for designated roles or accounts.
- Separate upload permissions from administrative configuration permissions. Use valid action names and specific bucket or object ARNs, and review conditions, other policies, and Block Public Access together.
- Configure upload monitoring and file inspection according to operational needs. These additional controls do not replace access restrictions.
Examples
These excerpts compare an upload grant with an explicit deny. They omit the definition of DOC-EXAMPLE-BUCKET; before deployment, provide bucket or object ARNs appropriate to the actions as well.
Incomplete upload grant
Resources:
SampleBucketPolicy3:
Type: "AWS::S3::BucketPolicy"
Properties:
Bucket: !Ref DOC-EXAMPLE-BUCKET
PolicyDocument:
Statement:
- Action: "PutObject"
Effect: Allow
Resource: "*"
Principal: "*"
PutObject lacks the required service prefix and is not a valid AWS policy action name. Even after changing it to s3:PutObject, the intended grant to every principal still needs to be restricted. Specify the required principals and object paths explicitly.
Explicit denial of object uploads
Resources:
SampleBucketPolicy1:
Type: "AWS::S3::BucketPolicy"
Properties:
Bucket: !Ref DOC-EXAMPLE-BUCKET
PolicyDocument:
Statement:
- Action:
- "s3:PutObject"
Effect: Deny
Resource: "*"
Principal: "*"
In a valid policy, Effect: Deny explicitly denies s3:PutObject on the specified resources to every principal and can block legitimate uploads too. It does not deny every other Put action. Design the allow and deny statements together with their resource scope so that required uploads remain possible.