Skip to main content

S3 Bucket Policy Has Excessive Permissions

Overview​

This checks S3 bucket policies for Statements that Allow Principals that include wildcard '*' groups.

Policies that allow wildcard groups will permit any user and/or AWS account to access or modify this bucket unless otherwise more explicitly denied permission by the policy.

Vendor​

AWS

Cloud Service​

S3

CSMM v1 DAT-02.1, S3.6

Severity​

4

Item Types​

AWS::S3::Bucket