Lucene search

K
osvGoogleOSV:GHSA-M26P-M559-G5J5
HistoryMay 01, 2022 - 6:45 p.m.

Legion of the Bouncy Castle Java Cryptography API Bleichenbacher Oracle Vulnerability

2022-05-0118:45:52
Google
osv.dev
8
java cryptography
bleichenbacher vulnerability
rsa cms
remote attack
crypto provider package

EPSS

0.006

Percentile

78.9%

The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to “a Bleichenbacher vulnerability in simple RSA CMS signatures without signed attributes.”

EPSS

0.006

Percentile

78.9%