Description
An S3 bucket policy allow statement with * in both Action and Principal can grant broad permissions to all principals. Effective access depends on the target resources, conditions, explicit denies, and Block Public Access settings. Access to internal data should be limited to the principals and operations required for its intended use.
Effect is a required policy element that specifies allow or deny. Omitting it neither grants access nor provides a way to restrict a policy.
Potential impact
- Unintended principals with object-read permission may obtain data.
- If writes or deletions are also allowed, added, changed, or removed objects can affect services and operational data.
- Relaxing other safeguards while leaving broad allow statements in place can expand access beyond its intended scope.
Remediation
- Remove unnecessary wildcard grants and specify the required accounts, roles, or services and actions.
s3:*still covers all S3 actions and is not a least-privilege replacement. - Use bucket or object ARNs appropriate to required actions such as
s3:GetObjectors3:PutObject. Review conditions and other allow/deny statements together, and retain Block Public Access for internal buckets. - Verify that required access works while unnecessary access is denied. If unintended public access occurred, restrict access and review relevant logs and change history.
Examples
These examples omit the definition of the referenced DOC-EXAMPLE-BUCKET. Supply the actual bucket definition and resource ARNs appropriate to each action. Neither example is a least-privilege deployment configuration to use unchanged.
Broad actions for all principals
Resources:
SampleBucketPolicy3:
Type: "AWS::S3::BucketPolicy"
Properties:
Bucket: !Ref DOC-EXAMPLE-BUCKET
PolicyDocument:
Statement:
- Action: "*"
Effect: Allow
Resource: "*"
Principal: "*"
This allow statement does not restrict principals or actions. If the policy is validly applied and other access controls do not block it, it can grant more permissions than needed.
Explicit GetObject deny
Resources:
SampleBucketPolicy1:
Type: "AWS::S3::BucketPolicy"
Properties:
Bucket: !Ref DOC-EXAMPLE-BUCKET
PolicyDocument:
Statement:
- Action:
- "s3:GetObject"
Effect: Deny
Resource: "*"
Principal: "*"
This statement explicitly denies s3:GetObject to all principals, so it can block legitimate object retrieval. It does not deny s3:GetObjectVersion, writes, or deletions. Check the actual target object ARNs and the effect on legitimate use before applying it.