Search CVE reports


Toggle filters

1 – 4 of 4 results


CVE-2021-40831

Medium priority
Ignored

The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on macOS systems. Additionally, SNI validation is also not enabled when the CA...

1 affected package

aws-c-io

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
aws-c-io Not in release Not in release Not in release
Show less packages

CVE-2021-40830

Medium priority
Ignored

The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on Unix systems. TLS handshakes will thus succeed if the peer can be verified...

1 affected package

aws-c-io

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
aws-c-io Not in release Not in release Not in release
Show less packages

CVE-2021-40829

Medium priority
Ignored

Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.4.2), Python (versions prior to 1.6.1), C++ (versions prior to 1.12.7) and Node.js (versions prior to 1.5.3) did not verify server certificate...

1 affected package

aws-c-io

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
aws-c-io Not in release Not in release Not in release
Show less packages

CVE-2021-40828

Medium priority
Ignored

Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions prior to 1.12.7) and Node.js (versions prior to 1.5.1) did not verify server certificate...

1 affected package

aws-c-io

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
aws-c-io Not in release Not in release Not in release
Show less packages