QID 981707

QID 981707: Java (maven) Security Update for org.bouncycastle:bcprov-jdk16 (GHSA-6xx3-rg99-gc3p)

Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.2.1, BC before 1.66, BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-6xx3-rg99-gc3p for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981707

    Software Advisories
    Advisory ID Software Component Link
    GHSA-6xx3-rg99-gc3p org.bouncycastle:bc-fips URL Logo github.com/advisories/GHSA-6xx3-rg99-gc3p
    GHSA-6xx3-rg99-gc3p org.bouncycastle:bcprov-ext-jdk15on URL Logo github.com/advisories/GHSA-6xx3-rg99-gc3p
    GHSA-6xx3-rg99-gc3p org.bouncycastle:bcprov-ext-jdk16 URL Logo github.com/advisories/GHSA-6xx3-rg99-gc3p
    GHSA-6xx3-rg99-gc3p org.bouncycastle:bcprov-jdk14 URL Logo github.com/advisories/GHSA-6xx3-rg99-gc3p
    GHSA-6xx3-rg99-gc3p org.bouncycastle:bcprov-jdk15 URL Logo github.com/advisories/GHSA-6xx3-rg99-gc3p
    GHSA-6xx3-rg99-gc3p org.bouncycastle:bcprov-jdk15on URL Logo github.com/advisories/GHSA-6xx3-rg99-gc3p
    GHSA-6xx3-rg99-gc3p org.bouncycastle:bcprov-jdk15to18 URL Logo github.com/advisories/GHSA-6xx3-rg99-gc3p
    GHSA-6xx3-rg99-gc3p org.bouncycastle:bcprov-jdk16 URL Logo github.com/advisories/GHSA-6xx3-rg99-gc3p