Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wg6q-6289-32hp

Опубликовано: 15 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.3

Описание

Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules

: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules).

PKIX draft CompositeVerifier accepts empty signature sequence as valid.

This issue affects BC-JAVA: from 1.49 before 1.84.

Пакеты

Наименование

org.bouncycastle:bcpkix-jdk18on

maven
Затронутые версииВерсия исправления

>= 1.49, < 1.84

1.84

Наименование

org.bouncycastle:bcpkix-jdk15to18

maven
Затронутые версииВерсия исправления

>= 1.49, < 1.84

1.84

Наименование

org.bouncycastle:bcpkix-jdk15on

maven
Затронутые версииВерсия исправления

>= 1.49, < 1.84

1.84

Наименование

org.bouncycastle:bcpkix-jdk14

maven
Затронутые версииВерсия исправления

>= 1.49, < 1.84

1.84

Наименование

org.bouncycastle:bcpkix-debug-jdk18on

maven
Затронутые версииВерсия исправления

>= 1.49, < 1.84

1.84

Наименование

org.bouncycastle:bcpkix-debug-jdk15to18

maven
Затронутые версииВерсия исправления

>= 1.49, < 1.84

1.84

Наименование

org.bouncycastle:bcpkix-debug-jdk14

maven
Затронутые версииВерсия исправления

>= 1.49, < 1.84

1.84

EPSS

Процентиль: 32%
0.00392
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java. This issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11.

CVSS3: 7.5
redhat
4 месяца назад

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java. This issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11.

CVSS3: 7.5
nvd
4 месяца назад

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java. This issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11.

CVSS3: 7.5
debian
4 месяца назад

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legi ...

suse-cvrf
3 месяца назад

Security update for bouncycastle

EPSS

Процентиль: 32%
0.00392
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-327