We found results for “”
CVE-2020-28052
Good to know:
Date: December 17, 2020
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
Language: Java
Severity Score
Related Resources (48)
Severity Score
Weakness Type (CWE)
Always-Incorrect Control Flow Implementation
CWE-670Top Fix
Upgrade Version
Upgrade to version org.bouncycastle:bcprov-jdk15to18:1.67,org.bouncycastle:bcprov-jdk15on:1.67,org.bouncycastle:bcprov-ext-jdk15on:1.67,org.bouncycastle:bcprov-ext-jdk14:1.67, org.bouncycastle:bcprov-debug-jdk15on:1.67
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |