Lucene search

K
githubGitHub Advisory DatabaseGHSA-V435-XC8X-WVR9
HistoryMay 14, 2024 - 3:32 p.m.

Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")

2024-05-1415:32:54
CWE-203
GitHub Advisory Database
github.com
14
bouncy castle
rsa
timing-based leakage
java tls
jsse provider

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

15.5%

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.

Affected configurations

Vulners
Node
bouncycastle.cryptographyRange<2.3.1
OR
bouncycastleRange<2.3.1
OR
org.bouncycastlebctls-jdk15to18Range<1.78
OR
org.bouncycastlebctls-jdk14Range<1.78
OR
org.bouncycastlebctls-jdk18onRange<1.78
OR
org.bouncycastlebcprov-jdk14Range<1.78
OR
org.bouncycastlebcprov-jdk15to18Range<1.78
OR
org.bouncycastlebcprov-jdk15onRange<1.78
OR
org.bouncycastlebcprov-jdk18onRange<1.78
OR
org.bouncycastlebctls-fipsRange<1.0.19
VendorProductVersionCPE
*bouncycastle.cryptography*cpe:2.3:a:*:bouncycastle.cryptography:*:*:*:*:*:*:*:*
*bouncycastle*cpe:2.3:a:*:bouncycastle:*:*:*:*:*:*:*:*
org.bouncycastlebctls-jdk15to18*cpe:2.3:a:org.bouncycastle:bctls-jdk15to18:*:*:*:*:*:*:*:*
org.bouncycastlebctls-jdk14*cpe:2.3:a:org.bouncycastle:bctls-jdk14:*:*:*:*:*:*:*:*
org.bouncycastlebctls-jdk18on*cpe:2.3:a:org.bouncycastle:bctls-jdk18on:*:*:*:*:*:*:*:*
org.bouncycastlebcprov-jdk14*cpe:2.3:a:org.bouncycastle:bcprov-jdk14:*:*:*:*:*:*:*:*
org.bouncycastlebcprov-jdk15to18*cpe:2.3:a:org.bouncycastle:bcprov-jdk15to18:*:*:*:*:*:*:*:*
org.bouncycastlebcprov-jdk15on*cpe:2.3:a:org.bouncycastle:bcprov-jdk15on:*:*:*:*:*:*:*:*
org.bouncycastlebcprov-jdk18on*cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:*:*:*:*:*:*:*:*
org.bouncycastlebctls-fips*cpe:2.3:a:org.bouncycastle:bctls-fips:*:*:*:*:*:*:*:*

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

15.5%