CVE-2025-14762

Description

A flaw was found in the AWS SDK for Ruby, an open-source client-side encryption library. A user with write access to an S3 (Simple Storage Service) bucket can exploit a missing cryptographic key commitment. This allows the introduction of a new Encrypted Data Key (EDK) that decrypts to different plaintext when stored in an "instruction file" instead of S3's metadata. This vulnerability can lead to data integrity issues, where encrypted data is incorrectly decrypted.

Statement

This vulnerability doesn't affect any supported Red Hat product.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Application Data

The confidentiality of sensitive data may be compromised by the use of a broken or risky cryptographic algorithm.

Integrity

Technical Impact: Modify Application Data

The integrity of sensitive data may be compromised by the use of a broken or risky cryptographic algorithm.

Accountability,Non-Repudiation

Technical Impact: Hide Activities

If the cryptographic algorithm is used to ensure the identity of the source of the data (such as digital signatures), then a broken algorithm will compromise this scheme and the source of the data cannot be proven.

Frequently Asked Questions

Want to get errata notifications? Sign up here.