Skip to content

Latest commit

 

History

History
19 lines (13 loc) · 851 Bytes

storage-bucket-all-users-policy.md

File metadata and controls

19 lines (13 loc) · 851 Bytes

CloudSploit

GOOGLE / Storage / Storage Bucket All Users Policy

Quick Info

Plugin Title Storage Bucket All Users Policy
Cloud GOOGLE
Category Storage
Description Ensures Storage bucket policies do not allow global write, delete, or read permissions
More Info Storage buckets can be configured to allow the global principal to access the bucket via the bucket policy. This policy should be restricted only to known users or accounts.
GOOGLE Link https://cloud.google.com/storage/docs/access-control/iam
Recommended Action Ensure that each storage bucket is configured so that no member is set to allUsers or allAuthenticatedUsers.

Detailed Remediation Steps