Inadequate Encryption Strength in aws-sdk-go - CVE-2022-2582
Published: March 27, 2024
Vulnerability identifier: #VU87857
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2582
CWE-ID: CWE-326
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. A remote user can gain unauthorized access to sensitive information on the system.
Affected software
aws-sdk-go
IBM Cloud Pak for Watson AIOps
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Cloud Pak for Watson AIOps
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
How to mitigate CVE-2022-2582
Install updates from vendor's website.
aws-sdk-go - update to 1.34.0
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.4