CVE-2020-8911

ADVISORY - golang

Summary

A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without computing a Message Authentication Code (MAC), which then allows an attacker who has write access to the target's S3 bucket and can observe whether or not an endpoint with access to the key can decrypt a file, they can reconstruct the plaintext with (on average) 128*length (plaintext) queries to the endpoint, by exploiting CBC's ability to manipulate the bytes of the next block and PKCS5 padding errors. It is recommended to update your SDK to V2 or later, and re-encrypt your files.

EPSS Score: 0.00209 (0.437)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Use of a Broken or Risky Cryptographic Algorithm

ADVISORY - github

Use of a Broken or Risky Cryptographic Algorithm

ADVISORY - gitlab

OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

Use of a Broken or Risky Cryptographic Algorithm

OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities

ADVISORY - redhat

Use of a Broken or Risky Cryptographic Algorithm


GoLang

CREATED

UPDATED

ADVISORY IDGO-2022-0646
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY
PackageTypeOS NameOS VersionAffected RangesFix Versions
github.com/aws/aws-sdk-gogolang-->=0Not yet available

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

ADVISORY IDCVE-2020-8911
EXPLOITABILITY SCORE

1.1

EXPLOITS FOUND
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

5.6medium

GitHub

CREATED

UPDATED

EXPLOITABILITY SCORE

1.1

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

5.6medium

GitLab

CREATED

UPDATED

ADVISORY ID

CVE-2020-8911

EXPLOITABILITY SCORE

1.1

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

5.6medium

Red Hat

CREATED

UPDATED

ADVISORY IDCVE-2020-8911
EXPLOITABILITY SCORE

1.1

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

5.6medium

Chainguard

CREATED

UPDATED

ADVISORY ID

CGA-5p79-wxp7-9267

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

Chainguard

CREATED

UPDATED

ADVISORY ID

CGA-wjr9-45cj-3vr5

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

intheWild

CREATED

UPDATED

ADVISORY IDCVE-2020-8911
EXPLOITABILITY SCORE

-

EXPLOITS FOUND

-

COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY