pkg:maven/BouncyCastle.Cryptography

Type maven
Name BouncyCastle.Cryptography

Known advisories, vulnerabilities and fixes for BouncyCastle.Cryptography package.

Moderate 3
Type Version Distribution # CVEs # Advisory ID Title Severity Published
Affected < 2.3.1 CVE-2024-29857
maven MAVEN:GHSA-8XFC-GM6G-VGPV Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation. moderate 2024-05-14T15:32:54
(5 weeks ago)
Fixed = 2.3.1 CVE-2024-29857
maven MAVEN:GHSA-8XFC-GM6G-VGPV Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation. moderate 2024-05-14T15:32:54
(5 weeks ago)
Affected < 2.3.1 CVE-2024-30172
maven MAVEN:GHSA-M44J-CFRM-G8QC Bouncy Castle crafted signature and public key can be used to trigger an infinite loop moderate 2024-05-14T15:32:54
(5 weeks ago)
Fixed = 2.3.1 CVE-2024-30172
maven MAVEN:GHSA-M44J-CFRM-G8QC Bouncy Castle crafted signature and public key can be used to trigger an infinite loop moderate 2024-05-14T15:32:54
(5 weeks ago)
Affected < 2.3.1 CVE-2024-30171
maven MAVEN:GHSA-V435-XC8X-WVR9 Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack") moderate 2024-05-14T15:32:54
(5 weeks ago)
Fixed = 2.3.1 CVE-2024-30171
maven MAVEN:GHSA-V435-XC8X-WVR9 Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack") moderate 2024-05-14T15:32:54
(5 weeks ago)
Loading...