Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-28052

Опубликовано: 18 дек. 2020
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

A flaw was found in bouncycastle. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password allowing incorrect passwords to indicate they were matching with previously hashed ones that were different. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Меры по смягчению последствий

Users unable to upgrade to version 1.67 or greater can copy the OpenBSDBCrypt.doCheckPassword() method implementation (https://github.com/bcgit/bc-java/blob/r1rv67/core/src/main/java/org/bouncycastle/crypto/generators/OpenBSDBCrypt.java#L259-L343) into their own utility class and supplement it with the required methods and variables as required

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of QuarkusbouncycastleNot affected
Red Hat Decision Manager 7bouncycastleNot affected
Red Hat OpenShift Application RuntimesbouncycastleNot affected
Red Hat Process Automation 7bouncycastleNot affected
Red Hat support for Spring BootbouncycastleNot affected
Red Hat Virtualization 4bouncycastleNot affected
Red Hat EAP-XP 2.0.0 via EAP 7.3.x basebouncycastleFixedRHSA-2021:275515.07.2021
Red Hat EAP-XP via EAP 7.3.x basebouncycastleFixedRHSA-2021:221002.06.2021
Red Hat Fuse 7.8.1karafFixedRHSA-2021:140127.04.2021
Red Hat Fuse 7.8.1spring-bootFixedRHSA-2021:140127.04.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1912881bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible

EPSS

Процентиль: 86%
0.0306
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 5 лет назад

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

CVSS3: 8.1
nvd
около 5 лет назад

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

CVSS3: 8.1
debian
около 5 лет назад

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 an ...

CVSS3: 8.1
github
почти 5 лет назад

Logic error in Legion of the Bouncy Castle BC Java

EPSS

Процентиль: 86%
0.0306
Низкий

8.1 High

CVSS3