RDS cluster exports snapshots to publicly accessible S3 bucket

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください

Description

A private RDS cluster is exporting database snapshots to a publicly accessible S3 bucket. This configuration can expose sensitive data to unauthorized users.

Remediation

  1. Update the S3 bucket configuration to disable public access. See the official documentation for more information on how to disable public access.
  2. Restrict access to the S3 bucket containing the snapshots to only the necessary users or roles by reviewing IAM policies and bucket resource policies. For more information on restricting access to an S3 bucket, see the official documentation.