Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade bouncycastle | Aug 3, 2023 | Jul 5, 2023 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 36440005 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 36454290 for version 14.1.1.0.0. | Apr 25, 2024 | Jul 5, 2023 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Jun 16, 2023 |
| Suse | — | Upgrade bouncycastle-mailUpgrade bouncycastle-pkixUpgrade bouncycastle-javadocUpgrade bouncycastle-tlsUpgrade bouncycastle-pgUpgrade bouncycastle-utilUpgrade bouncycastle-jmailUpgrade bouncycastle | Jul 18, 2023 | Jul 5, 2023 |
| Ubuntu | — | Upgrade libbcmail-java (Ubuntu Pro)Upgrade libbcutil-java (Ubuntu Pro)Upgrade libbcjmail-java (Ubuntu Pro)Upgrade libbcpg-java (Ubuntu Pro)Upgrade libbcpkix-java (Ubuntu Pro)Upgrade libbctls-java (Ubuntu Pro)Upgrade libbcprov-java (Ubuntu Pro) | Mar 19, 2026 | Jul 5, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub