[MAVEN:GHSA-WRWF-PMMJ-W989] Observable Discrepancy in BouncyCastle

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable application. This vulnerability is referred to as "ROBOT."

Package Affected Version
pkg:maven/org.bouncycastle/bcprov-jdk15on < 1.0.3
Package Fixed Version
pkg:maven/org.bouncycastle/bcprov-jdk15on = 1.0.3
ID
MAVEN:GHSA-WRWF-PMMJ-W989
Severity
moderate
URL
https://github.com/advisories/GHSA-wrwf-pmmj-w989
Published
2022-05-13T01:14:24
(2 years ago)
Modified
2023-01-27T05:02:14
(19 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.bouncycastle/bcprov-jdk15on org.bouncycastle bcprov-jdk15on < 1.0.3
Fixed pkg:maven/org.bouncycastle/bcprov-jdk15on org.bouncycastle bcprov-jdk15on = 1.0.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...