Ensure that your S3 buckets cannot be accessed for write actions by AWS authenticated accounts or IAM users in order to protect your S3 data from unauthorized access. An S3 bucket that allows WRITE (upload/delete) access to any AWS authenticated users can provide them the capability to add, delete and replace objects within the bucket without restrictions
Recommended Mitigation
Change the {AwsS3Bucket} bucket policy to block authenticated WRITE access