Lucene search

K
osvGoogleOSV:CVE-2020-15522
HistoryMay 20, 2021 - 12:15 p.m.

CVE-2020-15522

2021-05-2012:15:08
Google
osv.dev
9

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.9%

Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.