Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-21669

Опубликовано: 11 янв. 2024
Источник: nvd
CVSS3: 9.9
CVSS3: 8.8
EPSS Низкий

Описание

Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile environments. When verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation document.proof was not factored into the final verified value (true/false) on the presentation record. The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since version 0.7.0 and fixed in version 0.10.5.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:hyperledger:aries_cloud_agent:*:*:*:*:*:python:*:*
Версия от 0.7.0 (включая) до 0.10.5 (исключая)
cpe:2.3:a:hyperledger:aries_cloud_agent:0.11.0:rc1:*:*:*:python:*:*
cpe:2.3:a:hyperledger:aries_cloud_agent:0.11.0:rc2:*:*:*:python:*:*

EPSS

Процентиль: 34%
0.00136
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.9
github
около 2 лет назад

Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC

EPSS

Процентиль: 34%
0.00136
Низкий

9.9 Critical

CVSS3

8.8 High

CVSS3

Дефекты

CWE-347