AWS Security ChangesHomeSearch

AWS IAM: Added DynamoDB attributes without select security warning

Service: IAM · 2026-08-07 · Documentation high

File: IAM/latest/UserGuide/access-analyzer-reference-policy-checks.md · Type: authz

Summary

Added a new security warning for DynamoDB policies restricting dynamodb:Attributes without SPECIFIC_ATTRIBUTES select, preventing unintended data exposure.

Security assessment

The change documents a security best practice where missing dynamodb:Select=SPECIFIC_ATTRIBUTES could allow full item reads, addressing potential data leakage via authorization misconfiguration.

Evidence

## Security Warning – DynamoDB attributes without select

Diff

diff --git a/IAM/latest/UserGuide/access-analyzer-reference-policy-checks.md b/IAM/latest/UserGuide/access-analyzer-reference-policy-checks.md
index e00790277..630ff3bda 100644
--- a//IAM/latest/UserGuide/access-analyzer-reference-policy-checks.md
+++ b//IAM/latest/UserGuide/access-analyzer-reference-policy-checks.md
@@ -7 +7 @@
-Error – ARN account not allowedError – ARN Region not allowedError – Data type mismatchError – Duplicate keys with different caseError – Invalid actionError – Invalid ARN accountError – Invalid ARN prefixError – Invalid ARN RegionError – Invalid ARN resourceError – Invalid ARN service caseError – Invalid condition data typeError – Invalid condition key formatError – Invalid condition multiple BooleanError – Invalid condition operatorError – Invalid effectError – Invalid global condition keyError – Invalid partitionError – Invalid policy elementError – Invalid principal formatError – Invalid principal keyError – Invalid RegionError – Invalid serviceError – Invalid service condition keyError – Invalid service in actionError – Invalid variable for operatorError – Invalid versionError – Json syntax errorError – Json syntax errorError – Missing actionError – Missing ARN fieldError – Missing ARN RegionError – Missing effectError – Missing principalError – Missing qualifierError – Missing resourceError – Missing statementError – Null with if existsError – SCP syntax error action wildcardError – SCP syntax error principalError – Unique Sids requiredError – Unsupported action in policyError – Unsupported element combinationError – Unsupported global condition keyError – Unsupported principalError – Unsupported resource ARN in policyError – Unsupported SidError – Unsupported wildcard in principalError – Missing brace in variableError – Missing quote in variableError – Unsupported space in variableError – Empty variableError – Variable unsupported in elementError – Variable unsupported in versionError – Private IP addressError – Private NotIpAddressError – Policy size exceeds SCP quotaError – Invalid service principal formatError – Missing tag key in conditionError – Invalid vpc formatError – Invalid vpce formatError – Federated principal not supportedError – Unsupported action for condition keyError – Unsupported action in policyError – Unsupported resource ARN in policyError – Unsupported condition key for service principalError – Role trust policy syntax error notprincipalError – Role trust policy unsupported wildcard in principalError – Role trust policy syntax error resourceError – Type mismatch IP rangeError – Missing action for condition keyError – Invalid federated principal syntax in role trust policyError – Mismatched action for principalError – Missing action for roles anywhere trust policyError – Policy size exceeds RCP quotaError – RCP syntax error principalError – RCP syntax error allowError – RCP syntax error NotActionError – RCP syntax error actionError – Missing ARN accountError – Invalid kms key valueError – Variable usage too permissiveError – Wildcard usage too permissiveGeneral Warning – Create SLR with NotResourceGeneral Warning – Create SLR with star in action and NotResourceGeneral Warning – Create SLR with NotAction and NotResourceGeneral Warning – Create SLR with star in resourceGeneral Warning – Create SLR with star in action and resourceGeneral Warning – Create SLR with star in resource and NotActionGeneral Warning – Deprecated global condition keyGeneral Warning – Invalid date valueGeneral Warning – Invalid role referenceGeneral Warning – Invalid user referenceGeneral Warning – Missing versionGeneral Warning – Unique Sids recommendedGeneral Warning – Wildcard without like operatorGeneral Warning – Policy size exceeds identity policy quotaGeneral Warning – Policy size exceeds resource policy quotaGeneral Warning – Type mismatchGeneral Warning – Type mismatch BooleanGeneral Warning – Type mismatch dateGeneral Warning – Type mismatch numberGeneral Warning – Type mismatch stringGeneral Warning – Specific github repo and branch recommendedGeneral Warning – Policy size exceeds role trust policy quotaGeneral Warning – RCP missing related principal condition keyGeneral Warning – RCP missing related service principal condition keyGeneral Warning – RCP missing service condition key null checkGeneral Warning – Use condition key only with supported servicesSecurity Warning – Untrustworthy condition keySecurity Warning – Allow with NotPrincipalSecurity Warning – ForAllValues with single valued keySecurity Warning – Pass role with NotResourceSecurity Warning – Pass role with star in action and NotResourceSecurity Warning – Pass role with NotAction and NotResourceSecurity Warning – Pass role with star in resourceSecurity Warning – Pass role with star in action and resourceSecurity Warning – Pass role with star in resource and NotActionSecurity Warning – Missing paired condition keysSecurity Warning – Deny with unsupported tag condition key for serviceSecurity Warning – Deny NotAction with unsupported tag condition key for serviceSecurity Warning – Restrict access to service principalSecurity Warning – Missing condition key for oidc principalSecurity Warning – Missing github repo condition keySecurity Warning – String like operator with ARN condition keysSecurity Warning – ForAnyValue with audience claim typeSuggestion – Empty array actionSuggestion – Empty array conditionSuggestion – Empty array condition ForAllValuesSuggestion – Empty array condition ForAnyValueSuggestion – Empty array condition IfExistsSuggestion – Empty array principalSuggestion – Empty array resourceSuggestion – Empty object conditionSuggestion – Empty object principalSuggestion – Empty Sid valueSuggestion – Equivalent to null falseSuggestion – Equivalent to null trueSuggestion – Improve IP rangeSuggestion – Null with qualifierSuggestion – Private IP address subsetSuggestion – Private NotIpAddress subsetSuggestion – Redundant actionSuggestion – Redundant condition value numSuggestion – Redundant resourceSuggestion – Redundant statementSuggestion – Wildcard in service nameSuggestion – Allow with unsupported tag condition key for serviceSuggestion – Allow NotAction with unsupported tag condition key for serviceSuggestion – Recommended condition key for service principalSuggestion – Irrelevant condition key in policySuggestion – Redundant key due to wildcard in conditionSuggestion – Redundant principal in role trust policySuggestion – Redundant statement due to wildcard in conditionSuggestion – Confirm audience claim type
+Error – ARN account not allowedError – ARN Region not allowedError – Data type mismatchError – Duplicate keys with different caseError – Invalid actionError – Invalid ARN accountError – Invalid ARN prefixError – Invalid ARN RegionError – Invalid ARN resourceError – Invalid ARN service caseError – Invalid condition data typeError – Invalid condition key formatError – Invalid condition multiple BooleanError – Invalid condition operatorError – Invalid effectError – Invalid global condition keyError – Invalid partitionError – Invalid policy elementError – Invalid principal formatError – Invalid principal keyError – Invalid RegionError – Invalid serviceError – Invalid service condition keyError – Invalid service in actionError – Invalid variable for operatorError – Invalid versionError – Json syntax errorError – Json syntax errorError – Missing actionError – Missing ARN fieldError – Missing ARN RegionError – Missing effectError – Missing principalError – Missing qualifierError – Missing resourceError – Missing statementError – Null with if existsError – SCP syntax error action wildcardError – SCP syntax error principalError – Unique Sids requiredError – Unsupported action in policyError – Unsupported element combinationError – Unsupported global condition keyError – Unsupported principalError – Unsupported resource ARN in policyError – Unsupported SidError – Unsupported wildcard in principalError – Missing brace in variableError – Missing quote in variableError – Unsupported space in variableError – Empty variableError – Variable unsupported in elementError – Variable unsupported in versionError – Private IP addressError – Private NotIpAddressError – Policy size exceeds SCP quotaError – Invalid service principal formatError – Missing tag key in conditionError – Invalid vpc formatError – Invalid vpce formatError – Federated principal not supportedError – Unsupported action for condition keyError – Unsupported action in policyError – Unsupported resource ARN in policyError – Unsupported condition key for service principalError – Role trust policy syntax error notprincipalError – Role trust policy unsupported wildcard in principalError – Role trust policy syntax error resourceError – Type mismatch IP rangeError – Missing action for condition keyError – Invalid federated principal syntax in role trust policyError – Mismatched action for principalError – Missing action for roles anywhere trust policyError – Policy size exceeds RCP quotaError – RCP syntax error principalError – RCP syntax error allowError – RCP syntax error NotActionError – RCP syntax error actionError – Missing ARN accountError – Invalid kms key valueError – Variable usage too permissiveError – Wildcard usage too permissiveGeneral Warning – Create SLR with NotResourceGeneral Warning – Create SLR with star in action and NotResourceGeneral Warning – Create SLR with NotAction and NotResourceGeneral Warning – Create SLR with star in resourceGeneral Warning – Create SLR with star in action and resourceGeneral Warning – Create SLR with star in resource and NotActionGeneral Warning – Deprecated global condition keyGeneral Warning – Invalid date valueGeneral Warning – Invalid role referenceGeneral Warning – Invalid user referenceGeneral Warning – Missing versionGeneral Warning – Unique Sids recommendedGeneral Warning – Wildcard without like operatorGeneral Warning – Policy size exceeds identity policy quotaGeneral Warning – Policy size exceeds resource policy quotaGeneral Warning – Type mismatchGeneral Warning – Type mismatch BooleanGeneral Warning – Type mismatch dateGeneral Warning – Type mismatch numberGeneral Warning – Type mismatch stringGeneral Warning – Specific github repo and branch recommendedGeneral Warning – Policy size exceeds role trust policy quotaGeneral Warning – RCP missing related principal condition keyGeneral Warning – RCP missing related service principal condition keyGeneral Warning – RCP missing service condition key null checkGeneral Warning – Use condition key only with supported servicesSecurity Warning – Untrustworthy condition keySecurity Warning – Allow with NotPrincipalSecurity Warning – ForAllValues with single valued keySecurity Warning – Pass role with NotResourceSecurity Warning – Pass role with star in action and NotResourceSecurity Warning – Pass role with NotAction and NotResourceSecurity Warning – Pass role with star in resourceSecurity Warning – Pass role with star in action and resourceSecurity Warning – Pass role with star in resource and NotActionSecurity Warning – Missing paired condition keysSecurity Warning – Deny with unsupported tag condition key for serviceSecurity Warning – Deny NotAction with unsupported tag condition key for serviceSecurity Warning – Restrict access to service principalSecurity Warning – Missing condition key for oidc principalSecurity Warning – Missing github repo condition keySecurity Warning – String like operator with ARN condition keysSecurity Warning – DynamoDB attributes without selectSecurity Warning – ForAnyValue with audience claim typeSuggestion – Empty array actionSuggestion – Empty array conditionSuggestion – Empty array condition ForAllValuesSuggestion – Empty array condition ForAnyValueSuggestion – Empty array condition IfExistsSuggestion – Empty array principalSuggestion – Empty array resourceSuggestion – Empty object conditionSuggestion – Empty object principalSuggestion – Empty Sid valueSuggestion – Equivalent to null falseSuggestion – Equivalent to null trueSuggestion – Improve IP rangeSuggestion – Null with qualifierSuggestion – Private IP address subsetSuggestion – Private NotIpAddress subsetSuggestion – Redundant actionSuggestion – Redundant condition value numSuggestion – Redundant resourceSuggestion – Redundant statementSuggestion – Wildcard in service nameSuggestion – Allow with unsupported tag condition key for serviceSuggestion – Allow NotAction with unsupported tag condition key for serviceSuggestion – Recommended condition key for service principalSuggestion – Irrelevant condition key in policySuggestion – Redundant key due to wildcard in conditionSuggestion – Redundant principal in role trust policySuggestion – Redundant statement due to wildcard in conditionSuggestion – Confirm audience claim type
@@ -4372,0 +4373,31 @@ These AWS managed policies are exceptions to this security warning:
+## Security Warning – DynamoDB attributes without select
+
+**Issue code:** DYNAMODB_ATTRIBUTES_WITHOUT_SELECT
+
+**Finding type:** SECURITY_WARNING
+
+**Finding details**
+
+In the AWS Management Console, the finding for this check includes the following message:
+    
+    
+    DynamoDB attributes without select: Restricting dynamodb:Attributes without also setting dynamodb:Select to SPECIFIC_ATTRIBUTES allows all attributes to be returned on read requests that omit a projection expression. We recommend that you also set dynamodb:Select to SPECIFIC_ATTRIBUTES.
+
+In programmatic calls to the AWS CLI or AWS API, the finding for this check includes the following message:
+    
+    
+    "findingDetails": "Restricting dynamodb:Attributes without also setting dynamodb:Select to SPECIFIC_ATTRIBUTES allows all attributes to be returned on read requests that omit a projection expression. We recommend that you also set dynamodb:Select to SPECIFIC_ATTRIBUTES."
+
+**Resolving the security warning**
+
+Add a `StringEquals` condition that sets `dynamodb:Select` to `SPECIFIC_ATTRIBUTES` in the same statement as the `dynamodb:Attributes` condition. DynamoDB evaluates `dynamodb:Attributes` only for requests that specify the attributes to return. Without this condition, a read request that omits a projection expression returns the entire item.
+
+**Related terms**
+
+  * [Using IAM policy conditions for fine-grained access control](https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/specifying-conditions.html)
+
+  * [IAM JSON policy elements: Condition operators](./reference_policies_elements_condition_operators.html)
+
+
+
+