Skip to content

H3-2021-0001

Public Access to Amazon S3 Bucket

Category SECURITY_MISCONFIGURATION
Base Score 3.9

Description

An Amazon S3 bucket that your company may own is publicly accessible, either to everyone or any authenticated (cross-account) AWS user.

Impact

Attackers may be able to access sensitive data hosted in the bucket. Depending on bucket permissions, attackers may be able to delete objects in the bucket, upload new objects to the bucket, modify existing objects in the bucket, or modify bucket and object permissions

References