GO-2022-0635

    Dashboard / Vulnerabilities / GO-2022-0635

    GO-2022-0635

    Published: 12 Dec 2024Last Modified: 4 Feb 2026

    Summary: In-band key negotiation issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go

    Details: A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in the bucket, which can then allow them to change AES-GCM to AES-CTR. Using this in combination with a decryption oracle can reveal the authentication key used by AES-GCM as decrypting the GMAC tag leaves the authentication key recoverable as an algebraic equation. It is recommended to update your SDK to V2 or later, and re-encrypt your files.

    Affected packages

    Package

    Name: github.com/aws/aws-sdk-go

    Purl: pkg:golang/github.com/aws/aws-sdk-go

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High