The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash can be used to brute force the plaintext, if the hash is readable to the attacker. AWS now blocks this metadata field, but older SDK versions still send it.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published: 2022-12-27T21:13:47.272Z

Updated: 2024-08-03T00:39:08.166Z

Reserved: 2022-07-29T19:42:31.027Z

Link: CVE-2022-2582

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-12-27T22:15:12.390

Modified: 2023-01-05T04:43:35.213

Link: CVE-2022-2582

cve-icon Redhat

No data.