AWS library stored SQS payloads in S3 unencrypted for 4 years
Amazon's official SQS Extended Client Library stored large message payloads in S3 without server-side encryption from 2016 to 2020. The issue was only resolved in July 2020 with version 1.1.0, which added SSE-KMS support.
- The flaw affected HIPAA-regulated data, including patient records
- The fix shipped only in July 2020 with version 1.1.0
- The library creates S3 buckets programmatically, outside IaC templates
- Standard linters and AWS Config did not track violation duration
Read next
Security