Data at risk

S3 Bucket Allows Public DELETE

Platform(s)
Compliance Frameworks
  • HITRUST
  • ,
  • Mitre ATT&CK
  • ,
  • NIST 800-53
  • ,
  • Orca Best Practices

Description

Orca has detected that your s3 bucket '{AwsS3Bucket}' can be publicly accessed for DELETE actions. An S3 bucket that grants DELETE access to everyone can allow anonymous users to delete the objects within the bucket, leading to loss of data.