Skip to main content

OSS Bucket Public Read Prohibited

ID: rule:aliyun:oss-bucket-public-read-prohibited
Severity: high
IaC Types: ROS, Terraform

Description

Ensures OSS bucket ACL does not allow public read access.

Reason for Violation

The OSS bucket ACL allows public read access.

Recommendation

Set the bucket ACL to 'private' to prevent public read access.

Resource Types

  • ROS: ALIYUN::OSS::Bucket
  • Terraform: alicloud_oss_bucket