logo

Database

Aws Acl Public Buckets

Description

Detects S3 buckets that have dangerous public write permissions configured in their ACLs. When buckets grant WRITE, WRITE_ACP, or FULL_CONTROL permissions to AllUsers group, they become vulnerable to unauthorized modifications or deletions by anyone on the internet.

Detection Strategy

    Scans all S3 buckets in the AWS account

    Checks each bucket's ACL configuration for grants to the AllUsers group (http://acs.amazonaws.com/groups/global/AllUsers)

    Reports a vulnerability if any of these dangerous permissions are found: WRITE, WRITE_ACP, or FULL_CONTROL

    Each vulnerability includes the specific permission that was granted and its location in the ACL configuration