DirectorySecurity Advisories
Sign In
Security Advisories

CGA-585c-pgh6-jfxh

Published

Last updated

https://images.chainguard.dev/security/CGA-585c-pgh6-jfxh
Package

k3d

Latest Update
Fixed
Fixed Version

5.6.0-r11

Aliases
  • CVE-2022-2582
  • GHSA-6jvc-q2x7-pchv

Severity

4.3

Medium

CVSS V3

Summary

AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field

Description

The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash can be used to brute force the plaintext, if the hash is readable to the attacker. AWS now blocks this metadata field, but older SDK versions still send it.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images