Vulnerability library
Security checkJanuary 09, 2023

Improper Verification of Cryptographic Signature in aws-encryption-sdk-javascript

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

This advisory addresses several LOW severity issues with streaming signed messages and restricting processing of certain types of invalid messages.

This ESDK supports a streaming mode where callers may stream the plaintext of signed messages before the ECDSA signature is validated.

Recommendation

Update the @aws-crypto/client-browser package to the latest compatible version. Followings are version details:

  • Affected version(s): **>= 2.0.0, < 2.2.0 < 1.9.0**
  • Patched version(s): **2.2.0 1.9.0**

References

Could your website be exposed too?

SmartScanner can check your website for Improper Verification of Cryptographic Signature in aws-encryption-sdk-javascript and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated January 09, 2023