owasp-cloud-security icon indicating copy to clipboard operation
owasp-cloud-security copied to clipboard

S3 - A lack of centralised or automated pipelines leads to inconsistencies between the bucket policies for different buckets across the organisation, resulting in some buckets having poorly configured bucket policies

Open zeroXten opened this issue 8 years ago • 1 comments

zeroXten avatar Oct 22 '17 09:10 zeroXten

This is a really fascinating issue, its very different from "An attacker can read data." Does it fall into the same sort of threat? Worth thinking about. Also, this phrase "A lack of centralised or automated pipelines leads to " is cause, while "inconsistencies between the bucket policies for different buckets across the organisation" is state, and either

"some buckets having poorly configured bucket policies" or "buckets can be read by unauthorized parties"

is effect; but the second phrase loses the key "inconsistency" information.

adamshostack avatar Oct 22 '17 15:10 adamshostack