Review S3 public ACL handling

Ignore S3 public ACL permissions and remove unnecessary existing grants.

Description

On an S3 bucket that uses ACLs, public ACL permissions can allow external access unless they are ignored or otherwise blocked. IgnorePublicAcls: true ignores public ACL permissions on the bucket and its objects. It does not delete the ACLs or reject requests to set new public ACLs.

Effective access also depends on whether ACLs are enabled and on controls such as account-level blocks. New buckets have ACLs disabled by default, so this option alone does not establish public access.

Potential impact

  • Effective public read grants can expose object contents or listings.
  • Public access can return if a blocking setting is later removed while the public ACL remains.

Remediation

  • Set IgnorePublicAcls: true in PublicAccessBlockConfiguration.
  • Enable BlockPublicAcls to reject new public ACL requests, and review the other public-access blocks for private buckets.
  • Remove unnecessary public grants from existing ACLs and configure required access in policies.

Examples

These examples change the public ACL protections on the same bucket.

Before

yaml
Resources:
  Bucket13:
    Type: AWS::S3::Bucket
    Properties:
      PublicAccessBlockConfiguration:
        BlockPublicAcls: false
        BlockPublicPolicy: true
        IgnorePublicAcls: false
        RestrictPublicBuckets: true

Public ACL permissions are not ignored. Existing public grants can take effect if ACLs are enabled and no other control blocks them.

After

yaml
Resources:
  Bucket13:
    Type: AWS::S3::Bucket
    Properties:
      PublicAccessBlockConfiguration:
        BlockPublicAcls: true
        BlockPublicPolicy: true
        IgnorePublicAcls: true
        RestrictPublicBuckets: true

Public ACL permissions are ignored, and new public ACL requests are blocked. Existing ACLs are not automatically deleted; remove unnecessary grants separately.

References