S3 bucket policy uses wildcards for Action and Principal

Allowing wildcard actions for a wildcard principal in an S3 bucket policy can grant excessive access. Limit permissions to required principals, actions, and resources.

Description

An S3 bucket policy allow statement with * in both Action and Principal can grant broad permissions to all principals. Effective access depends on the target resources, conditions, explicit denies, and Block Public Access settings. Access to internal data should be limited to the principals and operations required for its intended use.

Effect is a required policy element that specifies allow or deny. Omitting it neither grants access nor provides a way to restrict a policy.

Potential impact

  • Unintended principals with object-read permission may obtain data.
  • If writes or deletions are also allowed, added, changed, or removed objects can affect services and operational data.
  • Relaxing other safeguards while leaving broad allow statements in place can expand access beyond its intended scope.

Remediation

  • Remove unnecessary wildcard grants and specify the required accounts, roles, or services and actions. s3:* still covers all S3 actions and is not a least-privilege replacement.
  • Use bucket or object ARNs appropriate to required actions such as s3:GetObject or s3:PutObject. Review conditions and other allow/deny statements together, and retain Block Public Access for internal buckets.
  • Verify that required access works while unnecessary access is denied. If unintended public access occurred, restrict access and review relevant logs and change history.

Examples

These examples omit the definition of the referenced DOC-EXAMPLE-BUCKET. Supply the actual bucket definition and resource ARNs appropriate to each action. Neither example is a least-privilege deployment configuration to use unchanged.

Broad actions for all principals

yaml
Resources:
  SampleBucketPolicy3:
    Type: "AWS::S3::BucketPolicy"
    Properties:
      Bucket: !Ref DOC-EXAMPLE-BUCKET
      PolicyDocument:
        Statement:
          - Action: "*"
            Effect: Allow
            Resource: "*"
            Principal: "*"

This allow statement does not restrict principals or actions. If the policy is validly applied and other access controls do not block it, it can grant more permissions than needed.

Explicit GetObject deny

yaml
Resources:
  SampleBucketPolicy1:
    Type: "AWS::S3::BucketPolicy"
    Properties:
      Bucket: !Ref DOC-EXAMPLE-BUCKET
      PolicyDocument:
        Statement:
          - Action:
              - "s3:GetObject"
            Effect: Deny
            Resource: "*"
            Principal: "*"

This statement explicitly denies s3:GetObject to all principals, so it can block legitimate object retrieval. It does not deny s3:GetObjectVersion, writes, or deletions. Check the actual target object ARNs and the effect on legitimate use before applying it.

References