CVE Vulnerabilities

CVE-2024-23680

Improper Verification of Cryptographic Signature

Published: Jan 19, 2024 | Modified: Nov 29, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

NameVendorStart VersionEnd Version
Aws_encryption_sdkAmazon*1.9.0 (excluding)
Aws_encryption_sdkAmazon2.0.0 (including)2.2.0 (excluding)

References