CVE-2025-14763
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-327
Uso de algoritmo criptográfico vulnerable o inseguro
Fecha de publicación:
17/12/2025
Última modificación:
17/12/2025
Descripción
*** Pendiente de traducción *** Missing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3&#39;s metadata record.<br />
<br />
<br />
To mitigate this issue, upgrade Amazon S3 Encryption Client for Java to version 4.0.0 or later.
Impacto
Puntuación base 4.0
6.00
Gravedad 4.0
MEDIA
Puntuación base 3.x
5.30
Gravedad 3.x
MEDIA



