QID 982263
QID 982263: Java (maven) Security Update for org.bouncycastle:bcprov-jdk15 (GHSA-xqj7-j8j5-f2xr)
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xqj7-j8j5-f2xr for updates pertaining to this vulnerability.
Vendor References
- GHSA-xqj7-j8j5-f2xr -
github.com/advisories/GHSA-xqj7-j8j5-f2xr
CVEs related to QID 982263
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xqj7-j8j5-f2xr | org.bouncycastle:bcprov-jdk14 |
|
|
| GHSA-xqj7-j8j5-f2xr | org.bouncycastle:bcprov-jdk15 |
|