« Back to list

Amazon

Amazon AWS S3 Crypto SDK: vulnerabilities and CVEs

Amazon AWS S3 Crypto SDK has 2 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-8912Low (2.5)0.23%—Aug 11, 2020
A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in…
CVE-2020-8911Medium (5.6)0.35%—Aug 11, 2020
A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without computing a Message Authentication Code (MAC), which then allows…

Other products by Amazon