Логотип exploitDog
bind:CVE-2025-14764
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-14764

Количество 2

Количество 2

nvd логотип

CVE-2025-14764

около 2 месяцев назад

Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade Amazon S3 Encryption Client for Go to version 4.0 or later.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3g75-q268-r9r6

около 2 месяцев назад

Amazon S3 Encryption Client has a Key Commitment Issue

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-14764

Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade Amazon S3 Encryption Client for Go to version 4.0 or later.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3g75-q268-r9r6

Amazon S3 Encryption Client has a Key Commitment Issue

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу