Lucene search

K
gitlabHttps://gitlab.com/gitlab-org/security-products/gemnasium-dbGITLAB-DD2CF2851BE8214C5A170502334B2481
HistoryMay 14, 2024 - 12:00 a.m.

Bouncy Castle crafted signature and public key can be used to trigger an infinite loop

2024-05-1400:00:00
https://gitlab.com/gitlab-org/security-products/gemnasium-db
gitlab.com
3
bouncy castle
java cryptography
apis
1.78
ed25519
verification code
infinite loop
issue
crafted signature
public key

6.4 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%

An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.

6.4 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%