A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committing property of AES-GCM (and other AEAD ciphers such as AES-GCM-SIV or (X)ChaCha20Poly1305) used by the SDKs to encrypt messages, an attacker can craft a unique cyphertext which will decrypt to multiple different results, and becomes especially relevant in a multi-recipient setting. We recommend users update their SDK to 2.0.0 or later.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-0050 A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committing property of AES-GCM (and other AEAD ciphers such as AES-GCM-SIV or (X)ChaCha20Poly1305) used by the SDKs to encrypt messages, an attacker can craft a unique cyphertext which will decrypt to multiple different results, and becomes especially relevant in a multi-recipient setting. We recommend users update their SDK to 2.0.0 or later.
Github GHSA Github GHSA GHSA-wqgp-vphw-hphf Security issues in AWS KMS and AWS Encryption SDKs: in-band protocol negotiation and robustness
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published:

Updated: 2024-08-04T10:12:10.984Z

Reserved: 2020-02-12T00:00:00

Link: CVE-2020-8897

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-16T12:15:14.557

Modified: 2024-11-21T05:39:39.220

Link: CVE-2020-8897

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses