QID 980871

QID 980871: Java (maven) Security Update for org.bouncycastle:bcprov-jdk15 (GHSA-rrvx-pwf8-p59p)

In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-rrvx-pwf8-p59p for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980871

    Software Advisories
    Advisory ID Software Component Link
    GHSA-rrvx-pwf8-p59p org.bouncycastle:bcprov-jdk14 URL Logo github.com/advisories/GHSA-rrvx-pwf8-p59p
    GHSA-rrvx-pwf8-p59p org.bouncycastle:bcprov-jdk15 URL Logo github.com/advisories/GHSA-rrvx-pwf8-p59p