QID 981321

QID 981321: Java (maven) Security Update for org.bouncycastle:bcprov-jdk14 (GHSA-4mv7-cq75-3qjm)

The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.2 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-4mv7-cq75-3qjm for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981321

    Software Advisories
    Advisory ID Software Component Link
    GHSA-4mv7-cq75-3qjm org.bouncycastle:bcprov-jdk14 URL Logo github.com/advisories/GHSA-4mv7-cq75-3qjm
    GHSA-4mv7-cq75-3qjm org.bouncycastle:bcprov-jdk15 URL Logo github.com/advisories/GHSA-4mv7-cq75-3qjm