QID 996832
Date Published: 2024-01-24
QID 996832: Java (Maven) Security Update for com.amazonaws:aws-encryption-sdk-java (GHSA-gvc7-gjrw-hj65)
AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-gvc7-gjrw-hj65 for updates and patch information.
Vendor References
- GHSA-gvc7-gjrw-hj65 -
github.com/advisories/GHSA-gvc7-gjrw-hj65
CVEs related to QID 996832
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gvc7-gjrw-hj65 | com.amazonaws:aws-encryption-sdk-java |
|