QID 995463
Date Published: 2023-10-03
QID 995463: Java (Maven) Security Update for bouncycastle:bcprov-jdk14 (GHSA-m26p-m559-g5j5)
The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "a Bleichenbacher vulnerability in simple RSA CMS signatures without signed attributes."
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-m26p-m559-g5j5 for updates and patch information.
Vendor References
- GHSA-m26p-m559-g5j5 -
github.com/advisories/GHSA-m26p-m559-g5j5
CVEs related to QID 995463
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m26p-m559-g5j5 | bouncycastle:bcprov-jdk14 |
|