Lucene search

K
githubGitHub Advisory DatabaseGHSA-6XX3-RG99-GC3P
HistoryAug 13, 2021 - 3:22 p.m.

Timing based private key exposure in Bouncy Castle

2021-08-1315:22:31
CWE-203
CWE-362
GitHub Advisory Database
github.com
117

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

47.9%

Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.2.1, BC before 1.66, BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.

Affected configurations

Vulners
Node
nugetbouncycastleRange<1.8.7
OR
org.bouncycastle\bcprovMatchjdk16
OR
org.bouncycastle\bcprovMatchjdk15to18
OR
org.bouncycastle\bcprovMatchjdk15on
OR
org.bouncycastle\bcprovMatchjdk15
OR
org.bouncycastle\bcprovMatchjdk14
OR
org.bouncycastle\bcprovMatchjdk16
OR
org.bouncycastle\bcprovMatchjdk15on
OR
org.bouncycastle\bcMatchfips

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

47.9%