Описание
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
A flaw was found in Bouncy Castle for Java. A remote attacker could exploit this by presenting a stapled Online Certificate Status Protocol (OCSP) response that is not properly bound to the certificate being checked. This vulnerability allows for a certificate validation bypass, potentially leading to applications accepting invalid or revoked certificates. This could enable man-in-the-middle attacks or unauthorized access.
Отчет
Important: This vulnerability in Bouncy Castle for Java allows a remote attacker to bypass certificate validation. By presenting a stapled OCSP response not properly bound to the certificate being checked, an attacker could cause applications to accept invalid or revoked certificates. This could facilitate man-in-the-middle attacks or unauthorized access in Red Hat products that rely on Bouncy Castle for certificate path validation.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Clients | bcprov-jdk15on | Not affected | ||
| Red Hat Ceph Storage 9 | ceph | Affected | ||
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Not affected | ||
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Not affected | ||
| Red Hat Enterprise Linux 9 | resteasy | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | bcpkix-jdk15on | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 7 | bcprov-jdk15on | Will not fix | ||
| Red Hat Single Sign-On 7 | bcpkix-jdk15on | Affected | ||
| Red Hat Single Sign-On 7 | bcprov-jdk15on | Affected |
Показывать по
Дополнительная информация
Статус:
7.4 High
CVSS3
Связанные уязвимости
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted ...
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
7.4 High
CVSS3