Description
An S3 bucket policy granting Get operations to all principals can expose information to unintended users or anonymous requests. The impact depends on the allowed action and resource. For example, s3:GetObject reads object contents, while s3:GetBucketLocation retrieves the bucket’s Region.
Conditions, explicit denies, Block Public Access and required KMS permissions can also limit actual access. A read grant does not itself authorize object modification or deletion.
Potential impact
- If object reads are actually allowed, log, backup or deployment-file contents may be exposed.
- Permitted configuration reads can disclose information about internal resources.
Remediation
- Remove unnecessary grants to all principals and specify only required accounts, roles or service principals.
- Scope permissions to action-appropriate resource ARNs and necessary conditions. For intentionally public data, allow only necessary read operations on the intended objects.
- Review Block Public Access and other policies, and verify that required access succeeds while unwanted access is denied. Investigate data and access records if exposure has already occurred.
Examples
These examples compare object-read permissions. Replace the bucket name and role ARN with usable values, and configure other public-access controls as needed.
Before
resource "aws_s3_bucket" "data_bucket" {
bucket = "my-tf-test-bucket"
}
resource "aws_s3_bucket_policy" "data_bucket_policy" {
bucket = aws_s3_bucket.data_bucket.id
policy = <<POLICY
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::my-tf-test-bucket/*"
}
]
}
POLICY
}
This statement grants every principal s3:GetObject on objects in the bucket. Anonymous requests may retrieve their contents if other controls do not block access.
After
resource "aws_s3_bucket" "data_bucket" {
bucket = "my-tf-test-bucket"
}
resource "aws_s3_bucket_policy" "data_bucket_policy" {
bucket = aws_s3_bucket.data_bucket.id
policy = <<POLICY
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::123456789012:role/app-reader"
},
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::my-tf-test-bucket/*"
}
]
}
POLICY
}
This statement limits its principal to the app-reader role. Review who can use the role and permissions from other policies; the change does not by itself remove every existing public-access path.