Description
AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gvc7-gjrw-hj65 | Improper Verification of Cryptographic Signature in aws-encryption-sdk-java |
Github GHSA |
GHSA-55xh-53m6-936r | Improper Verification of Cryptographic Signature in aws-encryption-sdk-java |
References
History
Sat, 29 Nov 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 29 Nov 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures. | AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures. |
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-14T22:54:42.027Z
Reserved: 2024-01-19T17:35:09.984Z
Link: CVE-2024-23680
Updated: 2024-08-01T23:06:25.440Z
Status : Modified
Published: 2024-01-19T21:15:10.140
Modified: 2026-06-17T07:13:22.463
Link: CVE-2024-23680
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-347
Improper Verification of Cryptographic Signature
Github GHSA