First published: Fri Jan 19 2024(Updated: )
AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.
Credit: disclosure@vulncheck.com disclosure@vulncheck.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.amazonaws:aws-encryption-sdk-java | >=2.0.0<2.2.0 | 2.2.0 |
maven/com.amazonaws:aws-encryption-sdk-java | <1.9.0 | 1.9.0 |
Amazon AWS Encryption SDK | <1.9.0 | |
Amazon AWS Encryption SDK | >=2.0.0<2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-23680 has not been specified, but it involves a vulnerability in signature validation.
To fix CVE-2024-23680, upgrade AWS Encryption SDK for Java to version 2.2.0 or to 1.9.0.
CVE-2024-23680 affects AWS Encryption SDK for Java versions from 2.0.0 to 2.2.0 and all versions less than 1.9.0.
Applications using vulnerable versions of the AWS Encryption SDK for Java for ECDSA signature validation are impacted by CVE-2024-23680.
The criticality of CVE-2024-23680 depends on your use of ECDSA signatures and the AWS Encryption SDK in your systems.