SiteShadow
Back to vulnerability library

CLOUD01 Insecure Cloud Storage ACLs

What this means

SiteShadow flagged cloud storage configuration that appears to allow broader access than intended (public buckets/blobs, permissive ACLs, or overly broad IAM policies).

Why it matters

Public buckets frequently expose sensitive data and backups.

Safer examples

1) Make private the default

Disable public access by default and require explicit, reviewed exceptions.

2) Use least-privilege IAM policies

3) Separate public assets from private data

If you have a public bucket for static assets, keep it completely separate from backups/exports/uploads.

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Request access View coverage