AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.amazonaws:aws-encryption-sdk-java(Maven) | 0 | 1.9.0 | N/A |
| com.amazonaws:aws-encryption-sdk-java(Maven) | 2.0.0 | 2.2.0 | N/A |
CVSS Metrics