Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-30171

Опубликовано: 18 апр. 2024
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.

A flaw was found in the Bouncy Castle Java cryptography APIs. Affected versions of the org.bouncycastle:bcprov-jdk18on package are vulnerable to Observable Timing Discrepancy via the PKCS#1 1.5 and OAEP decryption process (a.k.a. Marvin Attack). An attacker can recover cipher-texts via a side-channel attack by exploiting the Marvin security flaw. The PKCS#1 1.5 attack vector leaks data via javax.crypto.Cipher exceptions and the OAEP interface vector leaks via the bit size of the decrypted data.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 2org.bouncycastle-bcprov-jdk18onAffected
Red Hat build of Apache Camel 4 for Quarkus 3org.bouncycastle-bcprov-jdk18onAffected
Red Hat build of Apache Camel for Spring Boot 3org.bouncycastle-bcprov-jdk18onOut of support scope
Red Hat Build of Keycloakorg.bouncycastle-bcprov-jdk18onAffected
Red Hat build of Quarkusbcprov-jdk18onNot affected
Red Hat build of Quarkusbcprov-jdk18onNot affected
Red Hat Data Grid 8org.bouncycastle-bcprov-jdk18onNot affected
Red Hat Fuse 7org.bouncycastle-bcprov-jdk18onAffected
Red Hat JBoss Enterprise Application Platform Expansion Packorg.bouncycastle-bcprov-jdk18onNot affected
streams for Apache Kafkaorg.bouncycastle-bcprov-jdk18onNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2276360bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack)

EPSS

Процентиль: 57%
0.00901
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 2 лет назад

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.

CVSS3: 5.9
nvd
больше 2 лет назад

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.

CVSS3: 5.9
debian
больше 2 лет назад

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provide ...

suse-cvrf
около 2 лет назад

Security update for bouncycastle

suse-cvrf
больше 2 лет назад

Security update for bouncycastle

EPSS

Процентиль: 57%
0.00901
Низкий

5.9 Medium

CVSS3

Уязвимость CVE-2024-30171