Skip to main content

More Info:

AWS S3 buckets should not allow public READ_ACP access. Granting public “READ_ACP” access to your S3 buckets can allow everyone on the Internet to see who controls your objects. Malicious users can use this information to find S3 objects with misconfigured permissions and implement probing techniques to help them gain access to your S3 data.

Risk Level

Medium

Address

Security

Compliance Standards

  • APRA CPS 234 (Australia)
  • AWS Startup Security Baseline
  • BSI C5 (Germany)
  • Brazil LGPD
  • CCPA / CPRA (California)
  • CIS Critical Security Controls v8
  • CMMC 2.0
  • CSA Cloud Controls Matrix v4
  • DPDPA
  • Digital Operational Resilience Act (EU)
  • Essential 8
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 27701
  • KSA PDPL
  • MAS Technology Risk Management (Singapore)
  • MITRE ATT&CK (Cloud)
  • NIS2 Directive
  • NIST
  • NIST SP 800-171
  • NYDFS 23 NYCRR 500
  • PCI
  • SWIFT Customer Security Controls Framework
  • Sarbanes-Oxley IT General Controls
  • UK NCSC Cyber Assessment Framework

Triage and Remediation

Remediation

Using Console

Sure, here are the step by step instructions to remediate the misconfiguration “S3 Bucket Should Not Allow Public READ_ACP Access” for AWS using AWS console:
  1. Log in to your AWS console.
  2. Navigate to the S3 service.
  3. Select the S3 bucket that you want to remediate.
  4. Click on the “Permissions” tab.
  5. Scroll down to the “Access control list (ACL)” section.
  6. Click on the “Edit” button next to the “Public access” option.
  7. Uncheck the “List objects” checkbox under the “Access for Everyone” section.
  8. Click on the “Save” button to save the changes.
By following the above steps, you have successfully remediated the misconfiguration “S3 Bucket Should Not Allow Public READ_ACP Access” for AWS using AWS console.

To remediate the misconfiguration “S3 Bucket Should Not Allow Public READ_ACP Access” in AWS using AWS CLI, follow the below steps:Step 1: Open the AWS CLI on your local machine or EC2 instance.Step 2: Run the following command to list all the S3 buckets in your AWS account.
Step 3: Identify the bucket that has public READ_ACP access and note down the bucket name.Step 4: Run the following command to remove the public READ_ACP access from the identified S3 bucket.
Replace <bucket-name> with the name of the identified S3 bucket.Step 5: Verify that the public READ_ACP access has been removed from the S3 bucket by running the following command.
This command will return the access control list (ACL) of the S3 bucket. Ensure that there are no grants with the permission “READ_ACP” for “AllUsers” or “AuthenticatedUsers”.By following the above steps, you can remediate the misconfiguration “S3 Bucket Should Not Allow Public READ_ACP Access” in AWS using AWS CLI.
To remediate the S3 Bucket should not allow public READ_ACP access issue in AWS, you can follow the below steps using Python:
  1. Import the required AWS SDKs and libraries in your Python script.
  1. Initialize the S3 client using the AWS SDK for Python (Boto3) and provide the necessary AWS credentials.
  1. Iterate over all the S3 buckets in your AWS account and check if any of them have public READ_ACP access.
  1. If any S3 bucket has public READ_ACP access, update its bucket policy to deny public READ_ACP access.
This will update the bucket policy for the S3 bucket to deny public READ_ACP access.
Substitute:
  • REPLACE_WITH_BUCKET_NAME with the actual bucket name.
  • TARGET_BUCKET with your resource name if different.
This change does not force bucket replacement, but it may break workloads that depend on public access; review before applying.Verification: terraform plan should show creating or updating aws_s3_bucket_public_access_block.TARGET_BUCKET_block with all four attributes set to true.

Additional Reading: