An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade bouncycastle | Jul 30, 2024 | Dec 18, 2020 |
| Freebsd | — | Upgrade bouncycastle15 | Nov 4, 2022 | Aug 20, 2021 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 34686388 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 34653267 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 34697822 for version 12.2.1.3.0. | Jan 17, 2023 | Dec 18, 2020 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Dec 18, 2020 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | Dec 18, 2020 |
| Suse | — | Upgrade bouncycastle-pkixUpgrade bouncycastle-pgUpgrade bouncycastleUpgrade bouncycastle-mailUpgrade bouncycastle-tlsUpgrade bouncycastle-javadocUpgrade bouncycastle-util | Aug 9, 2024 | Dec 18, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub