Data at risk

S3 Bucket Policy allows cross account access via AWS service

Platform(s)
Compliance Frameworks

Brazilian General Data Protection (LGPD), CCPA, CPRA, Data Security Posture Management (DSPM) Best Practices, GDPR, HITRUST, iso_27001_2022, iso_27002_2022, Mitre ATT&CK, New Zealand Information Security Manual, NIST 800-171, NIST 800-53, Orca Best Practices, PDPA, UK Cyber Essentials

Description

Orca has detected a misconfigured S3 Bucket ({AwsS3Bucket}) policy which allows the service: {AwsS3Bucket.BucketPolicy.PolicyStatements.Principal|[Service]} to access the files in the bucket. Anyone using the service, including external users, can access the internal bucket files by utilizing the above principal.