AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.


Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gvc7-gjrw-hj65 Improper Verification of Cryptographic Signature in aws-encryption-sdk-java
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2024-09-10T20:17:04.595Z

Reserved: 2024-01-19T17:35:09.984Z

Link: CVE-2024-23680

cve-icon Vulnrichment

Updated: 2024-08-01T23:06:25.440Z

cve-icon NVD

Status : Modified

Published: 2024-01-19T21:15:10.140

Modified: 2024-11-21T08:58:09.597

Link: CVE-2024-23680

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.