Skip to main content

S3 Bucket Policy Has Excessive Permissions

Overview

This checks S3 bucket policies for Statements that Allow Principals that include wildcard '*' groups.

Policies that allow wildcard groups will permit any user and/or AWS account to access or modify this bucket unless otherwise more explicitly denied permission by the policy.

Vendor

AWS

Cloud Service

S3

CSMM v1 DAT-02.1, S3.6

Severity

4

Item Types

AWS::S3::Bucket