Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile environments. When verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation document.proof was not factored into the final verified value (true/false) on the presentation record. The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since version 0.7.0 and fixed in version 0.10.5.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21669.json",
"cwe_ids": [
"CWE-347"
],
"cna_assigner": "GitHub_M"
}{
"cpe": [
"cpe:2.3:a:hyperledger:aries_cloud_agent:*:*:*:*:*:python:*:*",
"cpe:2.3:a:hyperledger:aries_cloud_agent:0.11.0:rc1:*:*:*:python:*:*",
"cpe:2.3:a:hyperledger:aries_cloud_agent:0.11.0:rc2:*:*:*:python:*:*"
],
"source": [
"CPE_RANGE",
"CPE_STRING",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0.7.0"
},
{
"fixed": "0.10.5"
},
{
"introduced": "0.11.0-rc1"
},
{
"last_affected": "0.11.0-rc1"
},
{
"introduced": "0.11.0-rc2"
},
{
"last_affected": "0.11.0-rc2"
}
]
}