CVE Vulnerabilities

CVE-2024-23680

Improper Verification of Cryptographic Signature

Published: Jan 19, 2024 | Modified: Jan 26, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Aws_encryption_sdk Amazon * 1.9.0 (excluding)
Aws_encryption_sdk Amazon 2.0.0 (including) 2.2.0 (excluding)

References