Online Certificate Stapling Protocol (OCSP) Revocation check bypass
LowPublished Oct 12, 2020
OCSP Verification Bypass in s2n_x509_validator_validate_cert_stapled_ocsp_response() If a private key has been inappropriately disclosed, a malicious server may trick an s2n client into accepting a revoked certificate that uses OCSP stapling as the only revocation mechanism, provided the certificate and key are otherwise valid. s2n clients supporting TLS 1.3 and below are affected. No AWS service was affected by this issue. s2n users should update to the latest version of s2n. AWS SDK users should use the latest versions of the AWS SDKs as a best practice. All versions of s2n from commit [https://github.com/awslabs/s2n/commit/e954e6eff49d08a4aeab69c13c299ca0a2c8d65f](https://github.com/awslabs/s2n/commit/e954e6eff49d08a4aeab69c13c299ca0a2c8d65f) through commit [https://github.com/awslabs/s2n/commit/0df8de3c5630357ed25b935a5978c63f49bb4108](https://github.com/awslabs/s2n/commit/0df8de3c5630357ed25b935a5978c63f49bb4108) are affected by this issue. Affected s2n users should fetch s2n commit [https://github.com/awslabs/s2n/commit/b74b95563b14d4db50b53c07a779527b729a672e](https://github.com/awslabs/s2n/commit/b74b95563b14d4db50b53c07a779527b729a672e).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| s2n Product | < v0.10.19 | v0.10.19 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 162022 | Security vulnerability in a third party software, Slurm < 20.11.9 and 21.08.8 | Critical | 20.11.9 |
| May 52022 | Potential denial of service when sending version negotiation or close packets | Medium | v1.1.1 |
| May 192021 | Security vulnerability in a third party software, Slurm < 20.02.07 and 20.11.7 | High | 20.02.07and20.11.7 |
| Dec 142020 | Allocated memory not freed when session ticket is used | Low | v0.10.23 |
| Oct 122020 | Predictable IV in CBC-mode composite cipher suites | Low | v0.10.19 |
| Oct 122020 | Server denial-of-service via crafted handshake message | Low | v0.10.19 |