Skip to main content
emnode
Compliance Critical severity

AWS Security Hub · S3

S3.2: Public S3 buckets expose data to anyone on the internet

Written and reviewed by Emnode · Last reviewed

What does AWS Security Hub S3.2 check?

S3.2 fails any bucket whose ACL or policy allows public read access, i.e. anyone on the internet can list or download objects.

Why does S3.2 matter?

Public-read buckets are behind a large share of cloud data leaks: customer PII, backups, and credentials sitting one anonymous GET away. Attackers actively scan for them, and discovery is often automated within minutes of exposure. There is rarely a good reason for a data bucket to be world-readable.

How do I fix S3.2?

  1. Enable Block Public Access on the bucket to immediately cut public read.
  2. Remove the offending Principal "*" grants from the bucket policy and any public-read ACLs.
  3. For content that must be public, front it with CloudFront + OAC rather than exposing the bucket directly.

Remediation script · bash

# Close the highest-impact public exposure first: databases.
for db in $(aws rds describe-db-instances \
    --query 'DBInstances[?PubliclyAccessible==`true`].DBInstanceIdentifier' --output text); do
  aws rds modify-db-instance --db-instance-identifier "$db" \
    --no-publicly-accessible --apply-immediately
  echo "$db: public access removed"
done

# Ratchet S3 shut at the account level so no bucket can be made public again.
aws s3control put-public-access-block --account-id 123456789012 \
  --public-access-block-configuration \
    'BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true'

Full walkthrough (console steps, edge cases and verification) in the lesson Block public access to AWS resources.

Is S3.2 a false positive?

A bucket intentionally hosting public assets will still fail S3.2: the control is about whether the bucket is public, not whether you meant it to be. Use CloudFront for legitimate public content so the bucket itself can stay private.

Part of the learning path Trim your network spend
  • S3.1 Account-level S3 public access is not fully blocked
  • S3.3 Buckets can be written to by anyone on the internet
  • S3.5 S3 is accepting unencrypted HTTP requests
  • S3.6 Bucket policy grants broad access to other AWS accounts
  • S3.8 Buckets can still be made public; Block Public Access is off
  • S3.9 No S3 access logs, so reads and writes go unaudited
  • S3.10 Versioned buckets should have lifecycle configurations
  • S3.11 Buckets should have event notifications enabled
  • S3.12 ACLs should not be used to manage bucket access
  • S3.13 Buckets have no lifecycle rules and grow forever
  • S3.15 Buckets should have Object Lock enabled
  • S3.17 Buckets should be encrypted at rest with KMS keys