Plugin Title | Pre-Authenticated Requests Access |
Cloud | ORACLE |
Category | Object Store |
Description | Ensure that pre-authenticated requests have least privilege access. |
More Info | Pre-authenticated requests allow for users who are not in the tenancy to access buckets, ensuring least access prevents malicious entities from leveraging this type of access to edit or delete objects in a bucket. |
ORACLE Link | https://docs.cloud.oracle.com/iaas/Content/Object/Tasks/usingpreauthenticatedrequests.htm |
Recommended Action | When creating pre-authenticated Requests, ensure only object read permissions are selected. |