CVE-2024-23680
AWS Encryption SDK for Java Improper Verification of Cryptographic Signature
AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected products
com.amazonaws:aws-encryption-sdk-javaWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →