Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4446-656p-f54g

Опубликовано: 17 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Deserialization of Untrusted Data in Bouncy castle

Legion of the Bouncy Castle Java Cryptography APIs starting in version 1.57 and prior to version 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application.

This vulnerability appears to have been fixed in 1.60 and later.

Пакеты

Наименование

org.bouncycastle:bcprov-jdk15on

maven
Затронутые версииВерсия исправления

>= 1.57, < 1.60

1.60

EPSS

Процентиль: 88%
0.04043
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-470
CWE-502

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.

CVSS3: 4.9
redhat
почти 8 лет назад

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.

CVSS3: 9.8
nvd
больше 7 лет назад

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.

CVSS3: 9.8
debian
больше 7 лет назад

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptogra ...

suse-cvrf
больше 7 лет назад

Security update for bouncycastle

EPSS

Процентиль: 88%
0.04043
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-470
CWE-502