Vulnerabilities/

Improper Verification of Cryptographic Signature in aws-encryption-sdk-javascript

Severity:
Medium

Description

This advisory addresses several LOW severity issues with streaming signed messages and restricting processing of certain types of invalid messages.

This ESDK supports a streaming mode where callers may stream the plaintext of signed messages before the ECDSA signature is validated.

Recommendation

Update the @aws-crypto/client-browser package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@aws-crypto/client-browser
Anything's wrong? Let us know Last updated on January 09, 2023