CVE-2024-21669

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 11, 2024
Updated: Jan 20, 2024
CWE ID 347

Summary

CVE-2024-21669 is a vulnerability in Hyperledger Aries Cloud Agent Python (ACA-Py) versions 0.7.0 to 0.10.5. It affects products such as uOHmBV, uOHmBU, and others listed in the 'affected_products' field. The vulnerability allows holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs and enables malicious verifiers to save and replay a presentation from these holders as their own. The flaw occurs when verifying W3C Format Verifiable Credentials, and it results in the presentation record not factoring in the result of verifying the presentation document.proof. The potential danger is rated as HIGH with a base score of 8.8, impacting confidentiality, integrity, and availability. Remediation is possible by updating to version 0.10.5 or later of ACA-Py.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-21669 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options