First published: Fri Jan 19 2024(Updated: )
AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.
Credit: disclosure@vulncheck.com disclosure@vulncheck.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.amazonaws:aws-encryption-sdk-java | >=2.0.0<2.2.0 | 2.2.0 |
maven/com.amazonaws:aws-encryption-sdk-java | <1.9.0 | 1.9.0 |
Amazon Aws Encryption Sdk | <1.9.0 | |
Amazon Aws Encryption Sdk | >=2.0.0<2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.