Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-9340

Опубликовано: 22 авг. 2025
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher. This issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 8bc-fipsNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packbc-fipsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2390279org.bouncycastle/bc-fips: native encrypt/decrypt operations in JCE may corrupt data if same byte array used for input and output.

EPSS

Процентиль: 4%
0.0002
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

nvd
26 дней назад

Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher. This issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0.

github
26 дней назад

Bouncy Castle for Java has Out-of-Bounds Write Vulnerability

EPSS

Процентиль: 4%
0.0002
Низкий

5.9 Medium

CVSS3