CVE-2024-21669
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-21669 is a vulnerability in Hyperledger Aries Cloud Agent Python (ACA-Py) versions 0.7.0 to 0.10.5. It affects products such as uOHmBV, uOHmBU, and others listed in the 'affected_products' field. The vulnerability allows holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs and enables malicious verifiers to save and replay a presentation from these holders as their own. The flaw occurs when verifying W3C Format Verifiable Credentials, and it results in the presentation record not factoring in the result of verifying the presentation `document.proof`. The potential danger is rated as HIGH with a base score of 8.8, impacting confidentiality, integrity, and availability. Remediation is possible by updating to version 0.10.5 or later of ACA-Py.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Advisories, Assessments, and Mitigations
Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future
- Gain complete coverage of your cyber, third party, and physical attack surface
- Proactively mitigate threats before they turn into costly attacks
- Make fast, effective, data-driven decisions