Описание
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
A flaw was found in Bouncy Castle for Java. A remote attacker can exploit this vulnerability by providing a specially crafted BCFKS keystore file that specifies an unbounded Key Derivation Function (KDF) cost. This can lead to a Denial of Service (DoS) as the system attempts to process the file, consuming excessive resources and becoming unresponsive.
Отчет
Bouncy Castle for Java is bundled as a cryptographic provider across numerous Red Hat products. Loading a BCFKS keystore honors an unbounded Key Derivation Function (KDF) cost from the untrusted file, so loading a crafted keystore forces excessive computation and a denial of service. Exploitation requires the application to load an attacker-supplied BCFKS keystore file. Note: Red Hat rates this Important (CVSS v3 7.5, A:H) versus the upstream CVEORG v4 score of 5.3 (Moderate, A:L).
Меры по смягчению последствий
Red Hat is not aware of a mitigation for this flaw other than updating the affected Bouncy Castle component to a fixed version (bc-java 1.85, LTS 2.73.12, or BC-FJA bc-fips 1.0.2.7/2.0.2/2.1.3) once available for the affected product.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Clients | bcprov-jdk15on | Not affected | ||
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Not affected | ||
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Affected | ||
| Red Hat Enterprise Linux 9 | resteasy | Affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | bcprov-jdk15on | Will not fix | ||
| Red Hat Single Sign-On 7 | bcprov-jdk15on | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unb ...
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
7.5 High
CVSS3