Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-2582

Опубликовано: 27 дек. 2022
Источник: ubuntu
Приоритет: medium
CVSS3: 4.3

Описание

The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash can be used to brute force the plaintext, if the hash is readable to the attacker. AWS now blocks this metadata field, but older SDK versions still send it.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

not-affected

1.41.14-1ubuntu1
esm-apps/noble

not-affected

esm-apps/xenial

not-affected

focal

ignored

end of standard support, was needs-triage
jammy

not-affected

1.41.14-1ubuntu1
kinetic

not-affected

Показывать по

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 3 лет назад

The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash can be used to brute force the plaintext, if the hash is readable to the attacker. AWS now blocks this metadata field, but older SDK versions still send it.

CVSS3: 4.3
debian
около 3 лет назад

The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext along ...

CVSS3: 4.3
github
около 3 лет назад

AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field

4.3 Medium

CVSS3