github.com/aws/aws-cdk-go/awscdk/v2
AWS CDK bindings for Go.
Activity
- Latest release
- 3d ago
- Total releases
- 50
- Cadence
- ~27 days
- Last 12 months
- 7
Reach
- Stars
- 191
Details
- First release
- Jul 07, 2021
| Version | Released | |
|---|---|---|
v2.262.2
minor
|
v2.262.2
minor
Dependencies (5)
|
|
v2.258.0
minor
|
v2.258.0
minor
Dependencies (5)
|
|
v2.244.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.244.0
minor
Dependencies (5)
|
|
v2.239.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.239.0
minor
Dependencies (5)
|
|
v2.235.1
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.235.1
minor
Dependencies (5)
|
|
v2.232.1
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.232.1
minor
Dependencies (5)
|
|
v2.231.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.231.0
minor
Dependencies (5)
|
|
v2.208.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.208.0
minor
Dependencies (5)
|
|
v2.202.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.202.0
minor
Dependencies (5)
|
|
v2.201.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.201.0
minor
Dependencies (5)
|
|
v2.200.1
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.200.1
minor
Dependencies (5)
|
|
v2.197.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.197.0
minor
Dependencies (5)
|
|
v2.177.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.177.0
minor
Dependencies (6)
|
|
v2.173.1
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.173.1
minor
Dependencies (6)
|
|
v2.168.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.168.0
minor
Dependencies (6)
|
|
v2.162.1
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.162.1
minor
Dependencies (6)
|
|
v2.160.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.160.0
minor
Dependencies (6)
|
|
v2.148.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.148.0
minor
Dependencies (5)
|
|
v2.147.2
patch
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.147.2
patch
Dependencies (5)
|
|
v2.147.1
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.147.1
minor
Dependencies (5)
|
|
v2.145.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.145.0
minor
Dependencies (5)
|
|
v2.137.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.137.0
minor
Dependencies (5)
|
|
v2.136.1
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.136.1
minor
Dependencies (5)
|
|
v2.119.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.119.0
minor
Dependencies (5)
|
|
v2.108.1
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.108.1
minor
Dependencies (5)
|
|
v2.106.1
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.106.1
minor
Dependencies (5)
|
|
v2.104.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.104.0
minor
Dependencies (5)
|
|
v2.99.1
patch
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.99.1
patch
Dependencies (5)
|
|
v2.99.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.99.0
minor
Dependencies (5)
|
|
v2.95.1
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.95.1
minor
Dependencies (5)
|
|
v2.87.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.87.0
minor
Dependencies (5)
|
|
v2.86.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.86.0
minor
Dependencies (5)
|
|
v2.84.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.84.0
minor
Dependencies (5)
|
|
v2.71.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.71.0
minor
Dependencies (5)
|
|
v2.63.2
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.63.2
minor
Dependencies (5)
|
|
v2.56.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.56.0
minor
Dependencies (5)
|
|
v2.45.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.45.0
minor
Dependencies (2)
|
|
v2.44.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.44.0
minor
Dependencies (2)
|
|
v2.37.1
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.37.1
minor
Dependencies (2)
|
|
v2.21.1
patch
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.21.1
patch
Dependencies (2)
|
|
v2.21.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.21.0
minor
Dependencies (2)
|
|
v2.20.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.20.0
minor
Dependencies (2)
|
|
v2.16.0
minor
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.16.0
minor
Dependencies (2)
|
|
v2.5.0
initial
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.5.0
initial
Dependencies (2)
|
|
v2.0.0-rc.24
pre
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.0-rc.24
pre
Dependencies (2)
|
|
v2.0.0-rc.22
pre
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.0-rc.22
pre
Dependencies (2)
|
|
v2.0.0-rc.15
pre
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.0-rc.15
pre
Dependencies (2)
|
|
v2.0.0-rc.14
pre
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.0-rc.14
pre
Dependencies (2)
|
|
v2.0.0-rc.13
pre
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.0-rc.13
pre
Dependencies (2)
|
|
v2.0.0-rc.11
pre
1 CVE
GHSA-464c-974j-9xm6
Jul 24, 2026
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
SummaryThe AWS Cloud Development Kit (AWS CDK) is an open-source software development framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified an issue in which explicitly setting ImpactThe
Users who omit the property entirely are not affected, as Users affected by this issue could have CodeBuild S3 build logs stored using SSE-S3 (Amazon S3-managed keys, AES-256) rather than the AWS managed keys that CodeBuild applies by default. Since January 5, 2023, Amazon S3 automatically encrypts all new object uploads with SSE-S3, so logs written after that date remain encrypted at rest. However, logs written prior to that date to buckets that did not have default encryption configured at the time are potentially not encrypted at rest. Impacted versions: >= 1.75.0 and <= 2.252.0 PatchesThis issue has been addressed in WorkaroundsUsers who are unable to immediately upgrade to version 2.253.0 should omit the ReferencesIf you have any questions or comments about this advisory, contact AWS Security via our issue reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] https://aws.amazon.com/security/vulnerability-reporting/ AcknowledgementAWS thanks AISafe for collaborating on this issue through the coordinated disclosure process. Fixed in
2.253.0
References Updated Jul 24, 2026 · Source: OSV.dev |
v2.0.0-rc.11
pre
Dependencies (2)
|