AWS Security ChangesHomeSearch

AWS aurora-dsql: Correct vpcEndpointAccountId example values in CloudTrail log samples

Service: aurora-dsql · 2026-09-27 · Documentation low

File: aurora-dsql/latest/userguide/data-encryption.md

Summary

Updates two CloudTrail event examples (GenerateDataKey and Decrypt) so the vpcEndpointAccountId field shows "AWS Internal" instead of a placeholder VPC endpoint ID.

Security assessment

The change only corrects the illustrative value of a field in sample CloudTrail log output; it does not alter encryption behavior, key management guidance, or address any specific vulnerability.

Evidence

-        "vpcEndpointAccountId": "vpce-1a2b3c4d5e6f1a2b3",

Diff

diff --git a/aurora-dsql/latest/userguide/data-encryption.md b/aurora-dsql/latest/userguide/data-encryption.md
index 0edcfef8c..1e28dcb88 100644
--- a//aurora-dsql/latest/userguide/data-encryption.md
+++ b//aurora-dsql/latest/userguide/data-encryption.md
@@ -296 +296 @@ The event that records the `GenerateDataKey` operation is similar to the followi
-        "vpcEndpointAccountId": "vpce-1a2b3c4d5e6f1a2b3",
+        "vpcEndpointAccountId": "AWS Internal",
@@ -341 +341 @@ The event that records the `Decrypt` operation is similar to the following examp
-      "vpcEndpointAccountId": "vpce-1a2b3c4d5e6f1a2b3",
+      "vpcEndpointAccountId": "AWS Internal",