PT-2022-17545 · Amazon Web Services · Aws S3 Crypto Sdk

Published

2022-02-11

·

Updated

2023-01-05

·

CVE-2022-2582

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions AWS S3 Crypto SDK (affected versions not specified)
Description The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash can be used to brute force the plaintext, if the hash is readable to the attacker. The issue poses insider risks and privilege escalation risks, circumventing KMS controls for stored data. The attack is theoretically valid if the plaintext entropy is below the key size. The issue has been fully mitigated by AWS as of Aug. 5th by disallowing the header in question.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2022-2582
GHSA-6JVC-Q2X7-PCHV
GHSA-76WF-9VGP-PJ7W
GO-2022-0391

Affected Products

Aws S3 Crypto Sdk