Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xqj7-j8j5-f2xr

Опубликовано: 16 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.

Пакеты

Наименование

org.bouncycastle:bcprov-jdk14

maven
Затронутые версииВерсия исправления

< 1.60

1.60

Наименование

org.bouncycastle:bcprov-jdk15

maven
Затронутые версииВерсия исправления

< 1.60

1.60

Наименование

org.bouncycastle:bcprov-jdk15on

maven
Затронутые версииВерсия исправления

< 1.60

1.60

EPSS

Процентиль: 49%
0.00256
Низкий

7.5 High

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.

CVSS3: 4.8
redhat
почти 8 лет назад

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.

CVSS3: 7.5
nvd
больше 7 лет назад

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.

CVSS3: 7.5
debian
больше 7 лет назад

Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier h ...

suse-cvrf
больше 7 лет назад

Security update for bouncycastle

EPSS

Процентиль: 49%
0.00256
Низкий

7.5 High

CVSS3

Дефекты

CWE-327