High severityNVD Advisory· Published Nov 16, 2020· Updated Aug 4, 2024
Robustness weakness in AWS KMS and Encryption SDKs
CVE-2020-8897
Description
A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committing property of AES-GCM (and other AEAD ciphers such as AES-GCM-SIV or (X)ChaCha20Poly1305) used by the SDKs to encrypt messages, an attacker can craft a unique cyphertext which will decrypt to multiple different results, and becomes especially relevant in a multi-recipient setting. We recommend users update their SDK to 2.0.0 or later.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.amazonaws:aws-encryption-sdk-javaMaven | < 2.0.0 | 2.0.0 |
aws-encryption-sdkPyPI | < 2.0.0 | 2.0.0 |
Affected products
3- ghsa-coords2 versions
< 2.0.0+ 1 more
- (no CPE)range: < 2.0.0
- (no CPE)range: < 2.0.0
- Amazon/AWS SDKv5Range: stable
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-wqgp-vphw-hphfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-8897ghsaADVISORY
- aws.amazon.com/blogs/security/improved-client-side-encryption-explicit-keyids-and-key-commitmentghsaWEB
- aws.amazon.com/blogs/security/improved-client-side-encryption-explicit-keyids-and-key-commitment/mitrex_refsource_CONFIRM
- github.com/google/security-research/security/advisories/GHSA-wqgp-vphw-hphfghsax_refsource_CONFIRMWEB
- github.com/pypa/advisory-database/tree/main/vulns/aws-encryption-sdk/PYSEC-2020-261.yamlghsaWEB
News mentions
0No linked articles in our index yet.