Description
S3 BlockPublicPolicy rejects requests to save a bucket policy that S3 considers public. Disabling it does not itself make data public. New buckets have Block Public Access enabled by default, and omission from a template does not establish that the deployed protection is disabled.
The most restrictive applicable bucket-level, account-level and other Block Public Access settings take precedence. Enabling BlockPublicPolicy does not remove an existing policy, so current permissions still need review.
Potential impact
If a private bucket does not reject public-policy changes, a later mistaken grant can increase the risk of external data exposure. The effective exposure depends on the policy’s actions and resources and other access controls.
Remediation
- Explicitly enable all four Block Public Access options for private buckets.
- Remove unnecessary public permissions from existing bucket policies and ACLs, and check account-level settings.
- For intentional public services, review the required scope and alternative designs. Test that protection changes preserve legitimate service and required cross-account access.
Examples
The examples compare settings on the same bucket. Policies and ACLs grant permissions separately; these settings alone do not grant public object access.
Before
Resources:
Bucket13:
Type: AWS::S3::Bucket
Properties:
PublicAccessBlockConfiguration:
BlockPublicAcls: false
BlockPublicPolicy: false
IgnorePublicAcls: false
RestrictPublicBuckets: true
BlockPublicPolicy is disabled while RestrictPublicBuckets remains enabled. These controls serve different purposes, and applicable account-level protection must also be checked.
After
Resources:
Bucket13:
Type: AWS::S3::Bucket
Properties:
PublicAccessBlockConfiguration:
BlockPublicAcls: true
BlockPublicPolicy: true
IgnorePublicAcls: true
RestrictPublicBuckets: true
All four blocking options are enabled. This does not delete existing policies or ACLs, so remove unnecessary public grants and validate required access as well.