Aws S3 Server Side Encryption Disabled
Description
Detects S3 buckets with policies that explicitly disable server-side encryption requirements. Server-side encryption is a critical security control that protects data at rest in S3 buckets, and disabling it could expose sensitive data to unauthorized access.
Weakness:
099 - Non-encrypted confidential information - S3 Server Side Encryption
Category: Information Collection
Detection Strategy
• Scans all S3 buckets in the AWS account
• Examines each bucket's policy for Condition statements containing 's3:x-amz-server-side-encryption'
• Reports a vulnerability if a policy statement contains a Null condition that sets 's3:x-amz-server-side-encryption' to false
• Each reported vulnerability includes the specific policy statement location and the non-compliant condition value
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.