Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jfcv-jv9g-2vx2

Опубликовано: 22 авг. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.9

Описание

Bouncy Castle for Java has Uncontrolled Resource Consumption Vulnerability

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files org/bouncycastle/crypto/fips/AESNativeCBC.Java.

This issue affects Bouncy Castle for Java FIPS: from BC-FJA 2.1.0 through 2.1.0.

Пакеты

Наименование

org.bouncycastle:bc-fips

maven
Затронутые версииВерсия исправления

= 2.1.0

2.1.1

Наименование

org.bouncycastle:bctls-fips

maven
Затронутые версииВерсия исправления

= 2.73.7

2.73.8

EPSS

Процентиль: 3%
0.00019
Низкий

5.9 Medium

CVSS4

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.2
redhat
26 дней назад

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files org/bouncycastle/crypto/fips/AESNativeCBC.Java, org/bouncycastle/crypto/engines/AESNativeCBC.Java. This issue affects Bouncy Castle for Java FIPS: from BC-FJA 2.1.0 through 2.1.0; Bouncy Castle for Java LTS: from BC-LTS 2.73.0 through 2.73.7.

nvd
26 дней назад

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files org/bouncycastle/crypto/fips/AESNativeCBC.Java, org/bouncycastle/crypto/engines/AESNativeCBC.Java. This issue affects Bouncy Castle for Java FIPS: from BC-FJA 2.1.0 through 2.1.0; Bouncy Castle for Java LTS: from BC-LTS 2.73.0 through 2.73.7.

EPSS

Процентиль: 3%
0.00019
Низкий

5.9 Medium

CVSS4

Дефекты

CWE-400