Beveiligingsadvies

CVE-2026-3338

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-03-02 21:22:41
Laatst bijgewerkt 2026-08-21 12:12:53
Toegewezen door AMZN
CVSS-score 8.7
Status PUBLISHED

Beschrijving

Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.