Description
OSS static website hosting serves static files such as HTML and scripts. The feature is not inherently vulnerable: a website setting or internet endpoint alone does not enable anonymous reads. Actual public access depends on ACLs, policies and Block Public Access settings.
Keep website content separate from internal logs, backups and configuration files, and manage the intended publication scope explicitly.
Potential impact
- Public read grants can expose files or configuration information that was not intended for publication.
- Changing content stored in OSS requires separate write permissions, so access to upload paths also needs restriction.
Remediation
- Use
websiteonly where static hosting is needed, removing unnecessary configuration from internal storage. - Review permissions so only intended objects can be read publicly, and restrict writes and deletion to approved deployment identities.
- Check object ACLs and policies together, then test public and private content through the actual web access path.
Examples
These excerpts compare configurations with and without website settings. Keep the bucket name and Terraform resource address when modifying an existing bucket.
Website configuration
resource "alicloud_oss_bucket" "website_bucket" {
bucket = "bucket-1-website"
website {
index_document = "index.html"
error_document = "error.html"
}
}
Index and error documents are specified. This setting alone does not establish that files are public.
Configuration for private use
resource "alicloud_oss_bucket" "private_bucket" {
bucket = "bucket-1-acl"
acl = "private"
}
A private ACL is used without website settings. Also restrict separate policies and object ACLs to suit internal use.