CVE-2024-21669

Source
https://cve.org/CVERecord?id=CVE-2024-21669
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-21669.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-21669
Aliases
Published
2024-01-11T05:40:30Z
Modified
2026-08-19T11:48:38Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L CVSS Calculator
Summary
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
Details

Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile environments. When verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation document.proof was not factored into the final verified value (true/false) on the presentation record. The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since version 0.7.0 and fixed in version 0.10.5.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-347"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21669.json"
}
References

Affected packages

Git / github.com/openwallet-foundation/acapy

Affected ranges

Type
GIT
Repo
https://github.com/openwallet-foundation/acapy
Events
Database specific
Show details
{
    "cpe":  [
        "cpe:2.3:a:hyperledger:aries_cloud_agent:*:*:*:*:*:python:*:*",
        "cpe:2.3:a:hyperledger:aries_cloud_agent:0.11.0:rc1:*:*:*:python:*:*",
        "cpe:2.3:a:hyperledger:aries_cloud_agent:0.11.0:rc2:*:*:*:python:*:*"
    ],
    "extracted_events":  [
        {
            "introduced":  "0.7.0"
        },
        {
            "fixed":  "0.10.5"
        },
        {
            "introduced":  "0.11.0-rc1"
        },
        {
            "last_affected":  "0.11.0-rc1"
        },
        {
            "introduced":  "0.11.0-rc2"
        },
        {
            "last_affected":  "0.11.0-rc2"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.10.0
0.10.0-rc0
0.10.0-rc1
0.10.0-rc2
0.10.1
0.10.2
0.10.2-rc0
0.10.3
0.10.4
0.11.0-rc1
0.11.0-rc2
0.11.0rc2
0.7.0
0.7.1
0.7.1-rc0
0.7.2
0.7.2-rc0
0.7.3
0.7.3-rc0
0.7.4
0.7.4-rc0
0.7.4-rc1
0.7.4-rc2
0.7.4-rc3
0.7.4-rc4
0.7.4-rc5
0.8.0
0.8.0-rc0
0.8.1
0.8.1-rc0
0.8.1-rc1
0.8.1-rc2
0.8.2
0.8.2-rc0
0.8.2-rc1
0.8.2-rc2
0.9.0
0.9.0-rc0
1.*
1.0.0-rc0
1.0.0-rc1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-21669.json"