PT-2025-51884 · Amazon · Amazon S3 Encryption Client For Java

Antonf-Amzn

·

Publicado

2025-12-17

·

Atualizado

2025-12-21

·

CVE-2025-14763

CVSS v4.0

6.0

Média

VetorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Amazon S3 Encryption Client for Java versions prior to 4.0.0
Description A missing cryptographic key commitment in the Amazon S3 Encryption Client for Java could allow a user with write access to an S3 bucket to introduce a new Encryption Data Key (EDK) that decrypts to different plaintext. This is possible when the encrypted data key is stored in an instruction file instead of S3’s metadata record.
Recommendations Upgrade Amazon S3 Encryption Client for Java to version 4.0.0 or later.

Correção

Use of a Broken Cryptographic Algorithm

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-14763
GHSA-X44P-GVRJ-PJ2R

Produtos afetados

Amazon S3 Encryption Client For Java