s2n-tls could negotiate signature algorithms not allowed by policy
LowPublished Oct 5, 2023
### Impact s2n-tls clients and servers negotiating TLS1.2 could choose a SHA-1 hash in TLS connection signatures despite their s2n-tls security policy not supporting SHA-1. Customers of AWS services do not need to take action. Applications using s2n-tls should upgrade to the most recent release of s2n-tls. ### Patches The patch is included in s2n-tls v1.3.54 ### Workarounds There is no workaround. Applications using s2n-tls should upgrade to the most recent release of s2n-tls. If you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| s2n-tls Product | < 1.3.54 | 1.3.54 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 22024 | GHSA for sagemaker.base_deserializers.NumpyDeserializer | High7.8 | 2.218.0 |
| Dec 212023 | Potential URI resolution path traversal in the AWS SDK for PHP | Medium6.0 | 3.288.1 |
| Nov 62023 | Potential denial of service via crafted stream frames | Low | v1.31.0 |
| Jul 242023 | Potential denial of service after connection migration | Low | v1.25.0 |
| Jun 302023 | Potential denial of service when receiving empty UDP packets | Medium | v1.23.0 |
| Jun 192023 | EKS overly permissive trust policies | Medium6.6 | 2.80.0+1 more |