Vulnerabilities > Amazon > Amazon WEB Services AWS C IO > 0.10.7

DATE CVE VULNERABILITY TITLE RISK
2021-11-23 CVE-2021-40831 Improper Certificate Validation vulnerability in Amazon products
The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on macOS systems.
network
amazon CWE-295
6.0