Vulnerabilities > Amazon > AWS Encryption SDK > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-01-19 CVE-2024-23680 Improper Verification of Cryptographic Signature vulnerability in Amazon AWS Encryption SDK
AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.
network
low complexity
amazon CWE-347
5.3