[MAVEN:GHSA-4MV7-CQ75-3QJM] Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."

ID
MAVEN:GHSA-4MV7-CQ75-3QJM
Severity
moderate
URL
https://github.com/advisories/GHSA-4mv7-cq75-3qjm
Published
2018-10-17T16:27:50
(6 years ago)
Modified
2023-01-09T05:02:41
(20 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.bouncycastle/bcprov-jdk15 org.bouncycastle bcprov-jdk15 < 1.51
Fixed pkg:maven/org.bouncycastle/bcprov-jdk15 org.bouncycastle bcprov-jdk15 = 1.51
Affected pkg:maven/org.bouncycastle/bcprov-jdk14 org.bouncycastle bcprov-jdk14 < 1.51
Fixed pkg:maven/org.bouncycastle/bcprov-jdk14 org.bouncycastle bcprov-jdk14 = 1.51
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...