Skip to main content

OSS Bucket Authorize Specified IP

ID: rule:aliyun:oss-bucket-authorize-specified-ip
Severity: medium

Description

Ensures OSS bucket policies restrict access to specified IP ranges.

Reason for Violation

Restricting access by IP helps prevent unauthorized access even if credentials are compromised.

Recommendation

Add IP restriction conditions (acs:SourceIp) to the OSS bucket policy.

Resource Types

  • ALIYUN::OSS::Bucket