Boletines de Vulnerabilidades

Resolved: Application Load Balancer Session Ticket Issue


Información sobre el sistema

   
Software afectado AmazonWS

Descripción

Initial Publication Date: 2021/04/26 10:20 AM PDT On April 13th, 2021, AWS became aware of an edge case that affected how some Application Load Balancers (ALB) handled key rotation for TLS/SSL session ticket encryption. This edge case was introduced in September, 2020 and resulted in a small percentage of ALB traffic intermittently using an uninitialized session ticket encryption key. The edge case was triggered primarily during quiet periods of activity. ALBs with a high variation of traffic,

More info:

https://aws.amazon.com/security/security-bulletins/AWS-2021-002/

Identificadores estándar

Propiedad Valor
CVE

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2021-04-28

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT