Описание
In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
A flaw was found in Bouncy Castle for Java. The Certificate Request Message Format (CRMF) and Certificate Management Protocol (CMP) password-based Message Authentication Code (MAC) implementation allows for an unbounded iteration count. A remote attacker can exploit this by sending a specially crafted request, leading to a denial of service (DoS) due to excessive resource consumption.
Отчет
Bouncy Castle for Java is bundled as a cryptographic provider across numerous Red Hat products. The CRMF/CMP password-based MAC honors an unbounded iteration count, so a crafted request forces excessive computation and a denial of service. Exploitation requires the application to process attacker-supplied CRMF/CMP messages. Note: Red Hat rates this Important (CVSS v3 7.5, A:H) versus the upstream CVEORG v4 score of 6.9 (Moderate, A:L).
Меры по смягчению последствий
Red Hat is not aware of a mitigation for this flaw other than updating the affected Bouncy Castle component to a fixed version (bc-java 1.85, LTS 2.73.12, or BC-FJA bcpkix-fips 1.0.12/2.0.12/2.1.12) once available for the affected product.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat AMQ Clients | bcprov-jdk15on | Affected | ||
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Affected | ||
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Affected | ||
| Red Hat Enterprise Linux 9 | resteasy | Affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | bcprov-jdk15on | Will not fix | ||
| Red Hat Single Sign-On 7 | bcprov-jdk15on | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours u ...
In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
EPSS
7.5 High
CVSS3