Lucene search

K
githubGitHub Advisory DatabaseGHSA-73XV-W5GP-FRXH
HistoryApr 30, 2021 - 4:14 p.m.

Logic error in Legion of the Bouncy Castle BC Java

2021-04-3016:14:15
CWE-670
GitHub Advisory Database
github.com
58
bouncy castle java
logic error
openbsdbcrypt checkpassword

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.004

Percentile

74.4%

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

Affected configurations

Vulners
Node
org.bouncycastlebcprov-ext-jdk16Range1.651.67
OR
org.bouncycastlebcprov-jdk16Range1.651.67
OR
org.bouncycastlebcprov-jdk14Range1.651.67
OR
org.bouncycastlebcprov-ext-jdk15onRange1.651.67
OR
org.bouncycastlebcprov-jdk15onRange1.651.67
OR
org.bouncycastlebcprov-jdk15Range1.651.67
OR
org.bouncycastlebcprov-jdk15to18Range1.651.67
VendorProductVersionCPE
org.bouncycastlebcprov-ext-jdk16*cpe:2.3:a:org.bouncycastle:bcprov-ext-jdk16:*:*:*:*:*:*:*:*
org.bouncycastlebcprov-jdk16*cpe:2.3:a:org.bouncycastle:bcprov-jdk16:*:*:*:*:*:*:*:*
org.bouncycastlebcprov-jdk14*cpe:2.3:a:org.bouncycastle:bcprov-jdk14:*:*:*:*:*:*:*:*
org.bouncycastlebcprov-ext-jdk15on*cpe:2.3:a:org.bouncycastle:bcprov-ext-jdk15on:*:*:*:*:*:*:*:*
org.bouncycastlebcprov-jdk15on*cpe:2.3:a:org.bouncycastle:bcprov-jdk15on:*:*:*:*:*:*:*:*
org.bouncycastlebcprov-jdk15*cpe:2.3:a:org.bouncycastle:bcprov-jdk15:*:*:*:*:*:*:*:*
org.bouncycastlebcprov-jdk15to18*cpe:2.3:a:org.bouncycastle:bcprov-jdk15to18:*:*:*:*:*:*:*:*

References

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.004

Percentile

74.4%