Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-14762

Опубликовано: 17 дек. 2025
Источник: redhat
CVSS3: 5.3

Описание

Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade AWS SDK for Ruby to version 1.208.0 or later.

A flaw was found in the AWS SDK for Ruby, an open-source client-side encryption library. A user with write access to an S3 (Simple Storage Service) bucket can exploit a missing cryptographic key commitment. This allows the introduction of a new Encrypted Data Key (EDK) that decrypts to different plaintext when stored in an "instruction file" instead of S3's metadata. This vulnerability can lead to data integrity issues, where encrypted data is incorrectly decrypted.

Отчет

This vulnerability doesn't affect any supported Red Hat product.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-327
https://bugzilla.redhat.com/show_bug.cgi?id=2423393aws-sdk-ruby: AWS SDK for Ruby: Data integrity compromise via missing cryptographic key commitment

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
8 месяцев назад

Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade AWS SDK for Ruby to version 1.208.0 or later.

CVSS3: 5.3
nvd
8 месяцев назад

Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade AWS SDK for Ruby to version 1.208.0 or later.

CVSS3: 5.3
github
8 месяцев назад

AWS SDK for Ruby's S3 Encryption Client has a Key Commitment Issue

5.3 Medium

CVSS3