CVE-2024-23680

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:amazon:aws_encryption_sdk:*:*:*:*:*:*:*:*
cpe:2.3:a:amazon:aws_encryption_sdk:*:*:*:*:*:*:*:*

History

29 Nov 2025, 02:15

Type Values Removed Values Added
Summary (en) AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures. (en) AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

Information

Published : 2024-01-19 21:15

Updated : 2025-11-29 02:15


NVD link : CVE-2024-23680

Mitre link : CVE-2024-23680

CVE.ORG link : CVE-2024-23680


JSON object : View

Products Affected

amazon

  • aws_encryption_sdk
CWE
CWE-347

Improper Verification of Cryptographic Signature