Description
CloudTrail logs can contain sensitive audit information such as account activity and API calls. Remove public permissions from the log bucket and review actual bucket and object access together.
A public READ bucket ACL permits object listing; it does not by itself grant read access to every log object. Actual permissions also depend on object ACLs, bucket policies, Object Ownership and Block Public Access.
Potential impact
- Exposed object names or listings can help reveal the structure of an environment.
- If log-object read access is also public, account activity and operational information can be disclosed.
Remediation
- Remove public ACLs and unnecessary public bucket policies, and retain S3 Block Public Access.
- Configure required log-delivery and reader permissions in policies before disabling ACLs where possible. Restrict CloudTrail service writes, including an aws:SourceArn condition for the relevant trail ARN.
- Verify that logs continue to arrive and only approved auditors can read the objects they need.
Examples
These are comparison excerpts for an existing ACL-enabled environment. New S3 buckets disable ACLs by default and do not accept public ACL requests. Supply a unique bucket name and the CloudTrail delivery bucket policy separately.
Before
resource "aws_cloudtrail" "cloudtrail" {
name = "tf-trail-foobar"
s3_bucket_name = aws_s3_bucket.log_bucket.id
}
resource "aws_s3_bucket" "log_bucket" {
bucket = "my-tf-test-bucket"
acl = "public-read"
}
This requests a public READ bucket ACL. If effective, it permits listing; review log-object content access separately.
After
resource "aws_cloudtrail" "cloudtrail" {
name = "tf-trail-foobar"
s3_bucket_name = aws_s3_bucket.log_bucket.id
}
resource "aws_s3_bucket" "log_bucket" {
bucket = "my-tf-test-bucket"
acl = "private"
}
This removes public permissions from the bucket ACL. Also review bucket and object policies and Block Public Access while preserving CloudTrail delivery permissions.