Description
An S3 static website may intentionally serve public content. Website configuration alone does not make objects public, but public read permissions can make content available through the website endpoint. That endpoint does not support HTTPS.
Potential impact
Overbroad public permissions may expose files beyond the intended website, while HTTP traffic is vulnerable to interception or modification.
Remediation
Remove unused website configuration and revoke public permissions. If a site is needed, separate its public content and provide HTTPS. For a private bucket behind CloudFront, use the S3 REST origin with appropriate origin access control.
Examples
These excerpts remove the website configuration and apply S3 Block Public Access. Also review existing bucket policies and other access permissions.
Before
resource "aws_s3_bucket" "website_bucket" {
bucket = "s3-website-test.hashicorp.com"
}
resource "aws_s3_bucket_website_configuration" "website" {
bucket = aws_s3_bucket.website_bucket.id
index_document {
suffix = "index.html"
}
error_document {
key = "error.html"
}
}
After
resource "aws_s3_bucket" "website_bucket" {
bucket = "s3-website-test.hashicorp.com"
}
resource "aws_s3_bucket_public_access_block" "website_bucket" {
bucket = aws_s3_bucket.website_bucket.id
block_public_acls = true
block_public_policy = true
ignore_public_acls = true
restrict_public_buckets = true
}