Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9gp4-qrff-c648

Опубликовано: 18 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15

In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack. For BC 1.55 and older, in an environment where timings can be easily observed, it is possible with enough observations to identify when the decryption is failing due to padding.

Пакеты

Наименование

org.bouncycastle:bcprov-jdk14

maven
Затронутые версииВерсия исправления

< 1.56

1.56

Наименование

org.bouncycastle:bcprov-jdk15

maven
Затронутые версииВерсия исправления

< 1.56

1.56

Наименование

org.bouncycastle:bcprov-jdk15on

maven
Затронутые версииВерсия исправления

< 1.56

1.56

EPSS

Процентиль: 74%
0.00797
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 7 лет назад

In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack. For BC 1.55 and older, in an environment where timings can be easily observed, it is possible with enough observations to identify when the decryption is failing due to padding.

CVSS3: 4.8
redhat
почти 10 лет назад

In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack. For BC 1.55 and older, in an environment where timings can be easily observed, it is possible with enough observations to identify when the decryption is failing due to padding.

CVSS3: 5.9
nvd
больше 7 лет назад

In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack. For BC 1.55 and older, in an environment where timings can be easily observed, it is possible with enough observations to identify when the decryption is failing due to padding.

CVSS3: 5.9
debian
больше 7 лет назад

In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/E ...

suse-cvrf
больше 7 лет назад

Security update for bouncycastle

EPSS

Процентиль: 74%
0.00797
Низкий

5.9 Medium

CVSS3