Technical information leak In org.bouncycastle:bcprov-jdk15
Description
Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15 In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack. For BC 1.55 and older, in an environment where timings can be easily observed, it is possible with enough observations to identify when the decryption is failing due to padding.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 1.56-1 | ||
debian 13 | 1.56-1 | ||
maven | 1.56 | ||
maven | 1.56 | ||
maven | 1.56 | ||
debian 11 | 1.56-1 | ||
debian 14 | 1.56-1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10.
References
1. 2. 3. 4.