Advisories for Maven/Software.amazon.cryptography/Aws-Database-Encryption-Sdk-Dynamodb package

2023

Signing DynamoDB Sets when using the AWS Database Encryption SDK.

Impact This advisory addresses an issue when a DynamoDB Set attribute is marked as SIGN_ONLY in the AWS Database Encryption SDK (DB-ESDK) for DynamoDB. This also includes when a Set is part of a List or a Map. DB-ESDK for DynamoDB supports SIGN_ONLY and ENCRYPT_AND_SIGN attribute actions. In version 3.1.0 and below, when a Set type is assigned a SIGN_ONLY attribute action, there is a chance that signature validation of …