H3-2021-0001
Public Access to Amazon S3 Bucket
Category | SECURITY_MISCONFIGURATION |
Base Score | 3.9 |
Description
An Amazon S3 bucket that your company may own is publicly accessible, either to everyone or any authenticated (cross-account) AWS user.
Impact
Attackers may be able to access sensitive data hosted in the bucket. Depending on bucket permissions, attackers may be able to delete objects in the bucket, upload new objects to the bucket, modify existing objects in the bucket, or modify bucket and object permissions