CVE-2023-33201

CVSS v3.1 5.3 (Medium)
53% Progress
EPSS 0.08 % (37th)
0.08% Progress
Affected Products 1
Advisories 2

Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.

Weaknesses
CWE-295
Improper Certificate Validation
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2023-07-05 03:15:09
(14 months ago)
Updated Date
2023-08-24 19:15:38
(12 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Bouncycastle Bc-java prior 1.74 version cpe:2.3:a:bouncycastle:bc-java < 1.74
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...