logo

Database

Aws Private Buckets Not Blocking Acls

Description

Detects S3 buckets that are configured as private but do not have public access blocking settings enabled. This is a security risk since these buckets could be accidentally made public through bucket ACLs or policies, even if they are currently private. Having block public access settings disabled removes an important security safeguard.

Weakness:

325 - Excessive privileges - Wildcards

Category: Access Subversion

Detection Strategy

    Identifies all S3 buckets in the AWS account

    For each private bucket (skips already public buckets), checks if the Public Access Block configuration exists

    Reports a vulnerability if the Public Access Block configuration is missing entirely

    Reports a vulnerability for each public access block setting (BlockPublicAcls, BlockPublicPolicy, IgnorePublicAcls, RestrictPublicBuckets) that is set to false

Severity v4.0

0.5

Low

Method ID

CSPM-ATIOU

Technique

CSPM

Target

AWS

Technology

S3

CWE ID(s)

CWE-250