Missing Cryptographic Key Commitment in AWS SDK for Ruby
CVE-2025-14762
6MEDIUM
What is CVE-2025-14762?
The AWS SDK for Ruby, an open-source client-side encryption library, exhibits a vulnerability where a missing cryptographic key commitment could allow a user with write access to an S3 bucket to create a new Encrypted Data Key (EDK). This EDK could potentially decrypt to different plaintext when stored in an 'instruction file', rather than in S3's metadata record. Users are strongly advised to upgrade to version 1.208.0 or later to address this security concern.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AWS SDK for Ruby 1.208.0
References
CVSS V4
Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
