Data at risk

S3 Bucket Allows Authenticated WRITE Access

Risk Level

Hazardous (3)

Platform(s)

Description

Ensure that your S3 buckets cannot be accessed for write actions by AWS authenticated accounts or IAM users in order to protect your S3 data from unauthorized access. An S3 bucket that allows WRITE (upload/delete) access to any AWS authenticated users can provide them the capability to add, delete and replace objects within the bucket without restrictions
  • Recommended Mitigation

    Change the {AwsS3Bucket} bucket policy to block authenticated WRITE access