Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3286
HistoryJan 13, 2017 - 9:33 a.m.

Partial Key Validation

2017-01-1309:33:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.003 Low

EPSS

Percentile

71.0%

bouncycastle is vulnerable to partial key validation. The library doesn’t fully validate the other parties’ Diffie-Hellman key, meaning that invalid keys can reveal information about the other parties’ private key when static Diffie-Hellman is used.