Loading vulnerability details...
AWS-LC is an open-source, general-purpose cryptographic library.
Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer.
Customers of AWS services do not need to take action. aws-lc-sys contains code from AWS-LC. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys.
aws-lc-sys versions: >= 0.24.0, < 0.38.0
The patch is included in v0.38.0
There is no workaround. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys.
If there are any questions or comments about this advisory, contact [AWS/Amazon] Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue.
AWS-LC would like to thank Joshua Rogers (https://joshua.hu/) for collaborating on this issue through the coordinated vulnerability disclosure process.
AWS-LC is an open-source, general-purpose cryptographic library.
Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer.
Customers of AWS services do not need to take action. aws-lc-sys contains code from AWS-LC. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys.
aws-lc-sys versions: >= 0.24.0, < 0.38.0
The patch is included in v0.38.0
There is no workaround. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys.
If there are any questions or comments about this advisory, contact [AWS/Amazon] Security via the vulnerability reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue.
AWS-LC would like to thank Joshua Rogers (https://joshua.hu/) for collaborating on this issue through the coordinated vulnerability disclosure process.
This high-severity vulnerability could allow attackers to gain unauthorized access, execute arbitrary code, or compromise data integrity. Prompt remediation is strongly recommended.
Probability of exploitation in the next 30 days · more likely than 31.7% of all CVEs.
Apply security patches to version 0.38.0 immediately
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior