Description
CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected products
- Adobe / c2pa0.90.6
- Adobe / c2patool0.27.6
- Adobe / c2pa-web0.12.1
- Adobe / Content Credentials Command-Line Tool0 – c2patool-v0.27.5
- Adobe / Content Credentials Command-Line Toolc2patool-v0.27.6 – c2patool-v0.27.6
- Adobe / Content Credentials JS SDK0 – @contentauth/c2pa-web@0.12.0
- Adobe / Content Credentials JS SDK@contentauth/c2pa-web@0.12.1 – @contentauth/c2pa-web@0.12.1
- Adobe / Content Credentials Rust SDK0 – c2pa-v0.90.5
- Adobe / Content Credentials Rust SDKc2pa-v0.90.6 – c2pa-v0.90.6
References
Updated 5m ago · 8 sources