Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p93r-85wp-75v3

Опубликовано: 17 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.9

Описание

Bouncy Castle Has Covert Timing Channel Vulnerability

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java.

This issue only affects users of the FrodoKEM algorithm involved in the decryption of encapsulations.

This issue affects BC-JAVA: from 1.71 to 1.80.1, 1.81, 1.82 to 1.83.

Fixed versions: 1.80.2, 1.81.1, 1.84

Пакеты

Наименование

org.bouncycastle:bcprov-jdk15to18

maven
Затронутые версииВерсия исправления

>= 1.71, < 1.80.2

1.80.2

Наименование

org.bouncycastle:bcprov-jdk14

maven
Затронутые версииВерсия исправления

>= 1.81, < 1.81.1

1.81.1

Наименование

org.bouncycastle:bcprov-jdk18on

maven
Затронутые версииВерсия исправления

>= 1.82, < 1.84

1.84

EPSS

Процентиль: 49%
0.00691
Низкий

8.9 High

CVSS4

Дефекты

CWE-385

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

CVSS3: 7.5
redhat
4 месяца назад

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

CVSS3: 7.5
nvd
4 месяца назад

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

CVSS3: 7.5
debian
4 месяца назад

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc ...

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость файла FrodoEngine.Java криптографической библиотеки для платформы Java Bouncy Castle, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 49%
0.00691
Низкий

8.9 High

CVSS4

Дефекты

CWE-385