Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30614
HistoryMay 24, 2021 - 2:29 a.m.

Information Disclosure

2021-05-2402:29:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.001 Low

EPSS

Percentile

47.9%

bouncycastle is vulnerable to information disclosure. The vulnerability exists due to a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.