CVE-2025-14759

Severity CVSS v4.0:
MEDIUM
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
17/12/2025
Last modified:
17/12/2025

Description

Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3&amp;#39;s metadata record.<br /> <br /> To mitigate this issue, upgrade Amazon S3 Encryption Client for .NET to version 3.2.0 or later.