Описание
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
A flaw was found in Bouncy Castle for Java. The software fails to validate Diffie-Hellman peer values during key agreement. A remote attacker can exploit this flaw to compromise cryptographic keys, potentially leading to the decryption of sensitive communications or successful impersonation.
Отчет
This is an Important vulnerability where Bouncy Castle for Java, as used in Red Hat products, fails to validate Diffie-Hellman peer values during key agreement. This flaw allows a remote attacker to compromise cryptographic keys, potentially leading to the decryption of sensitive communications or successful impersonation, due to the low attack complexity and lack of required user interaction.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Not affected | ||
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Not affected | ||
| Red Hat Enterprise Linux 9 | resteasy | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | bcprov-jdk15on | Not affected | ||
| Red Hat Single Sign-On 7 | bcprov-jdk15on | Not affected |
Показывать по
Дополнительная информация
Статус:
7.4 High
CVSS3
Связанные уязвимости
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiat ...
In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
7.4 High
CVSS3