Public access enabled on an Alicloud OSS bucket

Review public OSS bucket ACLs and restrict unintended anonymous reads and writes.

Description

The OSS public-read ACL allows public reads, while public-read-write allows public reads and writes. Object ACLs, policies and Block Public Access also affect actual access and must be reviewed together.

An internet-reachable endpoint is different from permission for anonymous access. Use private for ordinary internal buckets, and clearly limit the purpose and scope of any public data.

Potential impact

  • The content of objects with effective public-read access may be exposed externally.
  • Public writes can allow unauthorized uploads, changes or deletion, affecting the service and storage costs.

Remediation

  • Set the bucket ACL to private and remove unnecessary public grants in object ACLs and bucket policies too.
  • Use Block Public Access for storage that need not be public, and verify actual request results.
  • Separate public content from internal data. Even where public reads are needed, restrict writing and administration to approved principals.

Examples

These compare ACL settings. Keep the same bucket name and Terraform resource address when modifying an existing bucket.

Before

hcl
resource "alicloud_oss_bucket" "public_bucket" {
  bucket = "bucket-170309-acl"
  acl    = "public-read"
}

A public-read ACL is requested. Object content may be exposed where other access controls do not prevent it.

After

hcl
resource "alicloud_oss_bucket" "private_bucket" {
  bucket = "bucket-170309-acl"
  acl    = "private"
}

The bucket ACL is private. Also check public grants in separately configured policies and object ACLs.

References