Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w285-wf9q-5w69

Опубликовано: 17 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

In Bouncy Castle JCE Provider the ECIES implementation allowed the use of ECB mode

In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.

Пакеты

Наименование

org.bouncycastle:bcprov-jdk14

maven
Затронутые версииВерсия исправления

< 1.56

1.56

Наименование

org.bouncycastle:bcprov-jdk15

maven
Затронутые версииВерсия исправления

< 1.56

1.56

Наименование

org.bouncycastle:bcprov-jdk15on

maven
Затронутые версииВерсия исправления

< 1.56

1.56

EPSS

Процентиль: 59%
0.00386
Низкий

7.4 High

CVSS3

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 7 лет назад

In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.

CVSS3: 4.8
redhat
почти 10 лет назад

In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.

CVSS3: 7.4
nvd
больше 7 лет назад

In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.

CVSS3: 7.4
debian
больше 7 лет назад

In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES i ...

suse-cvrf
больше 7 лет назад

Security update for bouncycastle

EPSS

Процентиль: 59%
0.00386
Низкий

7.4 High

CVSS3

Дефекты

CWE-326