[MAVEN:GHSA-M44J-CFRM-G8QC] Bouncy Castle crafted signature and public key can be used to trigger an infinite loop

Severity Moderate
Affected Packages 12
Fixed Packages 11
CVEs 1
ID
MAVEN:GHSA-M44J-CFRM-G8QC
Severity
moderate
URL
https://github.com/advisories/GHSA-m44j-cfrm-g8qc
Published
2024-05-14T15:32:54
(8 days ago)
Modified
2024-05-14T20:22:08
(8 days ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.bouncycastle/bctls-jdk18on org.bouncycastle bctls-jdk18on < 1.78
Fixed pkg:maven/org.bouncycastle/bctls-jdk18on org.bouncycastle bctls-jdk18on = 1.78
Affected pkg:maven/org.bouncycastle/bctls-jdk15to18 org.bouncycastle bctls-jdk15to18 < 1.78
Fixed pkg:maven/org.bouncycastle/bctls-jdk15to18 org.bouncycastle bctls-jdk15to18 = 1.78
Affected pkg:maven/org.bouncycastle/bctls-jdk14 org.bouncycastle bctls-jdk14 < 1.78
Fixed pkg:maven/org.bouncycastle/bctls-jdk14 org.bouncycastle bctls-jdk14 = 1.78
Affected pkg:maven/org.bouncycastle/bcprov-jdk18on org.bouncycastle bcprov-jdk18on < 1.78
Fixed pkg:maven/org.bouncycastle/bcprov-jdk18on org.bouncycastle bcprov-jdk18on = 1.78
Affected pkg:maven/org.bouncycastle/bcprov-jdk15to18 org.bouncycastle bcprov-jdk15to18 < 1.78
Fixed pkg:maven/org.bouncycastle/bcprov-jdk15to18 org.bouncycastle bcprov-jdk15to18 = 1.78
Affected pkg:maven/org.bouncycastle/bcprov-jdk15on org.bouncycastle bcprov-jdk15on < 1.78
Fixed pkg:maven/org.bouncycastle/bcprov-jdk15on org.bouncycastle bcprov-jdk15on = 1.78
Affected pkg:maven/org.bouncycastle/bcprov-jdk14 org.bouncycastle bcprov-jdk14 < 1.78
Fixed pkg:maven/org.bouncycastle/bcprov-jdk14 org.bouncycastle bcprov-jdk14 = 1.78
Affected pkg:maven/org.bouncycastle/bcpkix-jdk18on org.bouncycastle bcpkix-jdk18on < 1.78
Fixed pkg:maven/org.bouncycastle/bcpkix-jdk18on org.bouncycastle bcpkix-jdk18on = 1.78
Affected pkg:maven/org.bouncycastle/bcpkix-jdk15to18 org.bouncycastle bcpkix-jdk15to18 < 1.78
Fixed pkg:maven/org.bouncycastle/bcpkix-jdk15to18 org.bouncycastle bcpkix-jdk15to18 = 1.78
Affected pkg:maven/org.bouncycastle/bcpkix-jdk14 org.bouncycastle bcpkix-jdk14 < 1.78
Fixed pkg:maven/org.bouncycastle/bcpkix-jdk14 org.bouncycastle bcpkix-jdk14 = 1.78
Affected pkg:maven/BouncyCastle.Cryptography BouncyCastle.Cryptography < 2.3.1
Fixed pkg:maven/BouncyCastle.Cryptography BouncyCastle.Cryptography = 2.3.1
Affected pkg:maven/BouncyCastle BouncyCastle < 2.3.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...