An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade bouncycastle | May 15, 2025 | May 14, 2024 |
| Dell Powerstore Dsa2024462 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Nov 20, 2024 |
| Dell Powerstore Dsa2024497 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Dec 19, 2024 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Apr 18, 2024 |
| Suse | — | Upgrade bouncycastleUpgrade bouncycastle-tlsUpgrade bouncycastle-javadocUpgrade bouncycastle-pgUpgrade bouncycastle-mailUpgrade bouncycastle-pkixUpgrade bouncycastle-utilUpgrade bouncycastle-jmail | May 8, 2024 | May 7, 2024 |
| Ubuntu | — | Upgrade libbcjmail-java (Ubuntu Pro)Upgrade libbcpkix-java (Ubuntu Pro)Upgrade libbctls-java (Ubuntu Pro)Upgrade libbcprov-java (Ubuntu Pro)Upgrade libbcutil-java (Ubuntu Pro)Upgrade libbcmail-java (Ubuntu Pro)Upgrade libbcpg-java (Ubuntu Pro) | Mar 19, 2026 | May 14, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub