Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FN - S3 Buckets must not allow Get Action From All Principals #3751

Closed
securylight opened this issue Jun 23, 2021 · 1 comment · Fixed by #3887
Closed

FN - S3 Buckets must not allow Get Action From All Principals #3751

securylight opened this issue Jun 23, 2021 · 1 comment · Fixed by #3887
Assignees
Labels
bug Something isn't working help wanted Extra attention is needed needs-triage query New query feature

Comments

@securylight
Copy link

securylight commented Jun 23, 2021

Expected Behavior

S3 Buckets must not allow Get Action From All Principals

Actual Behavior

Get Action From All Principals with is allowed.

Steps to Reproduce the Problem

Scan a folder that contains the attached file
s3bucketGet_.tf.txt

Results are attached as well.
resultbucketget.html.txt

Also a Get request to the bucket.
s3bucketget

Specifications

  • Version: v1.3.2
  • Platform: Terraform
  • Subsystem:
@securylight securylight added the bug Something isn't working label Jun 23, 2021
@felipe-avelar felipe-avelar added community Community contribution needs-triage query New query feature labels Jun 28, 2021
@nunoocx nunoocx removed the community Community contribution label Jun 28, 2021
@felipe-avelar
Copy link
Contributor

felipe-avelar commented Jul 8, 2021

As observed #3789 , KICS does not supports jsonencode yet...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working help wanted Extra attention is needed needs-triage query New query feature
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants