Description
On an S3 bucket that uses ACLs, public ACL permissions can allow external access unless they are ignored or otherwise blocked. IgnorePublicAcls: true ignores public ACL permissions on the bucket and its objects. It does not delete the ACLs or reject requests to set new public ACLs.
Effective access also depends on whether ACLs are enabled and on controls such as account-level blocks. New buckets have ACLs disabled by default, so this option alone does not establish public access.
Potential impact
- Effective public read grants can expose object contents or listings.
- Public access can return if a blocking setting is later removed while the public ACL remains.
Remediation
- Set
IgnorePublicAcls: trueinPublicAccessBlockConfiguration. - Enable
BlockPublicAclsto reject new public ACL requests, and review the other public-access blocks for private buckets. - Remove unnecessary public grants from existing ACLs and configure required access in policies.
Examples
These examples change the public ACL protections on the same bucket.
Before
Resources:
Bucket13:
Type: AWS::S3::Bucket
Properties:
PublicAccessBlockConfiguration:
BlockPublicAcls: false
BlockPublicPolicy: true
IgnorePublicAcls: false
RestrictPublicBuckets: true
Public ACL permissions are not ignored. Existing public grants can take effect if ACLs are enabled and no other control blocks them.
After
Resources:
Bucket13:
Type: AWS::S3::Bucket
Properties:
PublicAccessBlockConfiguration:
BlockPublicAcls: true
BlockPublicPolicy: true
IgnorePublicAcls: true
RestrictPublicBuckets: true
Public ACL permissions are ignored, and new public ACL requests are blocked. Existing ACLs are not automatically deleted; remove unnecessary grants separately.