Legion of the Bouncy Castle Java Cryptography API Bleichenbacher Oracle Vulnerability
High severity
GitHub Reviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Sep 21, 2023
Description
Published by the National Vulnerability Database
Mar 30, 2009
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Sep 21, 2023
Reviewed
Sep 21, 2023
The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "a Bleichenbacher vulnerability in simple RSA CMS signatures without signed attributes."
References