CVE-2024-21669

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 11, 2024
Updated: Jan 20, 2024
CWE ID 347

Summary

CVE-2024-21669 is a vulnerability in Hyperledger Aries Cloud Agent Python (ACA-Py) versions 0.7.0 to 0.10.5. It affects products such as uOHmBV, uOHmBU, and others listed in the 'affected_products' field. The vulnerability allows holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs and enables malicious verifiers to save and replay a presentation from these holders as their own. The flaw occurs when verifying W3C Format Verifiable Credentials, and it results in the presentation record not factoring in the result of verifying the presentation `document.proof`. The potential danger is rated as HIGH with a base score of 8.8, impacting confidentiality, integrity, and availability. Remediation is possible by updating to version 0.10.5 or later of ACA-Py.

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-21669 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions