Логотип exploitDog
bind:CVE-2024-34447
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-34447

Количество 5

Количество 5

ubuntu логотип

CVE-2024-34447

почти 2 года назад

An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-34447

почти 2 года назад

An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-34447

почти 2 года назад

An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-34447

почти 2 года назад

An issue was discovered in the Bouncy Castle Crypto Package For Java b ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4h8f-2wvx-gg5w

почти 2 года назад

Bouncy Castle Java Cryptography API vulnerable to DNS poisoning

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-34447

An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-34447

An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-34447

An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-34447

An issue was discovered in the Bouncy Castle Crypto Package For Java b ...

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4h8f-2wvx-gg5w

Bouncy Castle Java Cryptography API vulnerable to DNS poisoning

CVSS3: 5.9
0%
Низкий
почти 2 года назад

Уязвимостей на страницу