[MAVEN:GHSA-4H8F-2WVX-GG5W] Bouncy Castle Java Cryptography API vulnerable to DNS poisoning

Severity Low
Affected Packages 5
Fixed Packages 5
CVEs 1

An issue was discovered in Bouncy Castle Java Cryptography APIs before BC 1.78. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.

ID
MAVEN:GHSA-4H8F-2WVX-GG5W
Severity
low
URL
https://github.com/advisories/GHSA-4h8f-2wvx-gg5w
Published
2024-05-03T18:30:37
(4 months ago)
Modified
2024-05-03T20:34:33
(4 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.bouncycastle/bcprov-jdk18on org.bouncycastle bcprov-jdk18on < 1.78
Fixed pkg:maven/org.bouncycastle/bcprov-jdk18on org.bouncycastle bcprov-jdk18on = 1.78
Affected pkg:maven/org.bouncycastle/bcprov-jdk15to18 org.bouncycastle bcprov-jdk15to18 < 1.78
Fixed pkg:maven/org.bouncycastle/bcprov-jdk15to18 org.bouncycastle bcprov-jdk15to18 = 1.78
Affected pkg:maven/org.bouncycastle/bcprov-jdk14 org.bouncycastle bcprov-jdk14 < 1.78
Fixed pkg:maven/org.bouncycastle/bcprov-jdk14 org.bouncycastle bcprov-jdk14 = 1.78
Affected pkg:maven/org.bouncycastle/bcprov-jdk13 org.bouncycastle bcprov-jdk13 < 1.78
Fixed pkg:maven/org.bouncycastle/bcprov-jdk13 org.bouncycastle bcprov-jdk13 = 1.78
Affected pkg:maven/org.bouncycastle/bcprov-jdk12 org.bouncycastle bcprov-jdk12 < 1.78
Fixed pkg:maven/org.bouncycastle/bcprov-jdk12 org.bouncycastle bcprov-jdk12 = 1.78
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...