Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade AWS SDK for Ruby to version 1.208.0 or later.
History

Fri, 19 Dec 2025 00:15:00 +0000

Type Values Removed Values Added
Title aws-sdk-ruby: AWS SDK for Ruby: Data integrity compromise via missing cryptographic key commitment
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 18 Dec 2025 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Amazon
Amazon aws Sdk Ruby
Vendors & Products Amazon
Amazon aws Sdk Ruby

Wed, 17 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Description The AWS SDK for Ruby is an open-source client-side encryption library used to facilitate writing and reading encrypted records to S3. Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade AWS SDK for Ruby to version 1.208.0 or later. Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade AWS SDK for Ruby to version 1.208.0 or later.
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 17 Dec 2025 21:00:00 +0000


Wed, 17 Dec 2025 20:30:00 +0000

Type Values Removed Values Added
Description The AWS SDK for Ruby is an open-source client-side encryption library used to facilitate writing and reading encrypted records to S3. Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade AWS SDK for Ruby to version 1.208.0 or later.
Weaknesses CWE-327
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2025-12-17T21:06:49.328Z

Reserved: 2025-12-16T00:24:31.398Z

Link: CVE-2025-14762

cve-icon Vulnrichment

Updated: 2025-12-17T20:35:53.947Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-17T21:15:53.517

Modified: 2025-12-18T15:07:42.550

Link: CVE-2025-14762

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-12-17T20:15:57Z

Links: CVE-2025-14762 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-12-18T09:57:10Z