Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-73xv-w5gp-frxh

Опубликовано: 30 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Logic error in Legion of the Bouncy Castle BC Java

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

Ссылки

Пакеты

Наименование

org.bouncycastle:bcprov-jdk15to18

maven
Затронутые версииВерсия исправления

>= 1.65, < 1.67

1.67

Наименование

org.bouncycastle:bcprov-jdk15

maven
Затронутые версииВерсия исправления

>= 1.65, < 1.67

1.67

Наименование

org.bouncycastle:bcprov-jdk15on

maven
Затронутые версииВерсия исправления

>= 1.65, < 1.67

1.67

Наименование

org.bouncycastle:bcprov-ext-jdk15on

maven
Затронутые версииВерсия исправления

>= 1.65, < 1.67

1.67

Наименование

org.bouncycastle:bcprov-jdk14

maven
Затронутые версииВерсия исправления

>= 1.65, < 1.67

1.67

Наименование

org.bouncycastle:bcprov-jdk16

maven
Затронутые версииВерсия исправления

>= 1.65, < 1.67

1.67

Наименование

org.bouncycastle:bcprov-ext-jdk16

maven
Затронутые версииВерсия исправления

>= 1.65, < 1.67

1.67

EPSS

Процентиль: 86%
0.0306
Низкий

8.1 High

CVSS3

Дефекты

CWE-670

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 5 лет назад

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

CVSS3: 8.1
redhat
около 5 лет назад

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

CVSS3: 8.1
nvd
около 5 лет назад

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

CVSS3: 8.1
debian
около 5 лет назад

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 an ...

EPSS

Процентиль: 86%
0.0306
Низкий

8.1 High

CVSS3

Дефекты

CWE-670