Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3291
HistoryJan 16, 2017 - 2:25 a.m.

Information Diclosure

2017-01-1602:25:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.004 Low

EPSS

Percentile

73.1%

bouncycastle is vulnerable to timing attacks. Due to the lack of blinding, a malicious user can monitor the time taken to generate a signature to gain information about the signatures k value and eventually the private value.