S3 bucket ACL allows read or write to all users 이 페이지는 아직 한국어로 제공되지 않습니다. 번역 작업 중입니다.
현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우
언제든지 연락주시기 바랍니다. Id: cloudformation-aws-s3-bucket-acl-allows-read-or-write-to-all-users
Provider: AWS
Platform: CloudFormation
Severity: Critical
Category: Access Control
Learn More Description S3 buckets must not use a public read-write ACL because it allows anyone on the internet to read, upload, modify, or delete objects. This risks data exposure, integrity loss, and service abuse. Check AWS::S3::Bucket resources and ensure the AccessControl property is not set to PublicReadWrite. Resources with AccessControl: PublicReadWrite will be flagged. Set AccessControl to Private or omit the ACL and enforce least-privilege access using bucket policies and a PublicAccessBlockConfiguration (enable BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, and RestrictPublicBuckets) to prevent accidental public access.
Secure configuration example:
MyBucket :
Type : AWS::S3::Bucket
Properties :
BucketName : my-bucket
AccessControl : Private
PublicAccessBlockConfiguration :
BlockPublicAcls : true
IgnorePublicAcls : true
BlockPublicPolicy : true
RestrictPublicBuckets : true
Compliant Code Examples AWSTemplateFormatVersion : 2010-09-09
Description : Creating S3 bucket
Resources :
JenkinsArtifacts03 :
Type : AWS::S3::Bucket
Properties :
AccessControl : BucketOwnerFullControl
BucketName : jenkins-artifacts
VersioningConfiguration :
Status : Enabled
Tags :
- Key : CostCenter
Value : ITEngineering
- Key : Type
Value : CICD
AWSTemplateFormatVersion : 2010-09-09
Description : Creating S3 bucket
Resources :
JenkinsArtifacts04 :
Type : AWS::S3::Bucket
Properties :
AccessControl : Private
BucketName : jenkins-secret-artifacts
VersioningConfiguration :
Status : Enabled
Tags :
- Key : CostCenter
Value : ''
AWSTemplateFormatVersion : 2010-09-09
Description : Creating S3 bucket
Resources :
JenkinsArtifacts05 :
Type : AWS::S3::Bucket
Properties :
AccessControl : PublicRead
BucketName : jenkins-secret-artifacts2
VersioningConfiguration :
Status : Enabled
Tags :
- Key : CostCenter
Value : ITEngineering
Non-Compliant Code Examples AWSTemplateFormatVersion : 2010-09-09
Description : Creating S3 bucket
Resources :
JenkinsArtifacts01 :
Type : AWS::S3::Bucket
Properties :
AccessControl : PublicReadWrite
BucketName : jenkins-artifacts
Tags :
- Key : CostCenter
Value : ITEngineering
AWSTemplateFormatVersion : 2010-09-09
Description : Creating S3 bucket
Resources :
StaticPage01 :
Type : AWS::S3::Bucket
Properties :
AccessControl : PublicReadWrite
BucketName : public-read-static-page01
WebsiteConfiguration :
ErrorDocument : 404. html
IndexDocument : index.html
Tags :
- Key : CostCenter
Value : ITEngineering
AWSTemplateFormatVersion : 2010-09-09
Description : Creating S3 bucket
Resources :
JenkinsArtifacts02 :
Type : AWS::S3::Bucket
Properties :
AccessControl : PublicReadWrite
BucketName : jenkins-artifacts-block-public
PublicAccessBlockConfiguration :
BlockPublicPolicy : false
VersioningConfiguration :
Status : Enabled
Tags :
- Key : CostCenter
Value : ITEngineering
- Key : Type
Value : CICD