CVE-2025-14760
Severity CVSS v4.0:
MEDIUM
Type:
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Publication date:
17/12/2025
Last modified:
17/12/2025
Description
Missing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3&#39;s metadata record.<br />
<br />
To mitigate this issue, upgrade AWS SDK for C++ to version 1.11.712 or later
Impact
Base Score 4.0
6.00
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM



