Lucene search

K
redhatcveRedhat.comRH:CVE-2020-8912
HistoryAug 18, 2020 - 7:29 p.m.

CVE-2020-8912

2020-08-1819:29:55
redhat.com
access.redhat.com
38

0.0004 Low

EPSS

Percentile

13.0%

A flaw was found in the AWS S3 Crypto SDK where algorithm parameters for the data encryption key are not authenticated. This flaw allows attackers with S3 bucket write access to change the negotiated encryption algorithm, potentially providing viable brute force methods to recover plaintext. This is not an issue in V2 of the API or for applications not encrypting files in S3 buckets. The highest threat from this vulnerability is to confidentiality.

0.0004 Low

EPSS

Percentile

13.0%