PT-2023-32985 · Amazon · Aws Database Encryption Sdk (Db-Esdk) For Dynamodb

Publicado

2023-11-09

·

Atualizado

2023-11-09

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Name of the Vulnerable Software and Affected Versions AWS Database Encryption SDK (DB-ESDK) for DynamoDB versions 3.1.0 and below
Description The issue arises when a DynamoDB Set attribute is marked as SIGN ONLY in the AWS Database Encryption SDK (DB-ESDK) for DynamoDB, including when a Set is part of a List or a Map. In versions 3.1.0 and below, signature validation of the record containing a Set may fail on read, even if the Set attributes contain the same values, due to the undefined order of elements in the Set returned by DynamoDB. This update ensures that any Set values are canonicalized in the same order while written to and read from DynamoDB.
Recommendations For AWS Database Encryption SDK (DB-ESDK) for DynamoDB versions 3.1.0 and below, upgrade to version 3.1.1 as soon as possible to address the issue.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

GHSA-72FP-W44G-625Q

Produtos afetados

Aws Database Encryption Sdk (Db-Esdk) For Dynamodb