CVE-2025-23206 | aws aws-cdk 2.148.1 IAM OIDC Custom Resource Provider Package tls.connect signature verification
A vulnerability was found in aws aws-cdk 2.148.1. It has been rated as problematic. Impacted is the function tls.connect of the component IAM OIDC Custom Resource Provider Package. This manipulation causes improper verification of cryptographic signature.
This vulnerability is registered as CVE-2025-23206. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.