Property
Languagejson
Severitymedium
CWECWE-264: CWE CATEGORY: Permissions, Privileges, and Access Controls
OWASPA01:2021 - Broken Access Control
Confidence LevelMedium
Impact LevelHigh
Likelihood LevelLow

Description#

This S3 bucket policy allows public (everyone) access by setting the Principal to ‘*’, making the bucket or its contents accessible to anyone on the internet. Such configurations expose your data to unauthorized users.

Impact#

If exploited, attackers or unintended users could view, download, modify, or delete files in your S3 bucket, leading to data leaks, loss of sensitive information, or potential service disruption. This can result in reputational damage, regulatory penalties, and loss of customer trust.