Insecure encryption algorithm In org.bouncycastle:bcprov-jdk15on
Description
Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 1.60 | ||
maven | 1.60 | ||
debian 11 | 1.59-2 | ||
debian 12 | 1.59-2 | ||
maven | 1.60 | ||
debian 13 | 1.59-2 | ||
debian 14 | 1.59-2 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14.