VDB
Sign up
MEDIUM

GHSA-c3fc-8qff-9hwx

Bouncy Castle has an LDAP injection

Quick fix

GHSA-c3fc-8qff-9hwx — org.bouncycastle:bcprov-jdk14: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcprov-jdk14

Details

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper.

This issue affects BC-JAVA: from 1.74 before 1.84.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.bouncycastle:bcprov-jdk14
Introduced in: 1.74Fixed in: 1.84
Fix# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcprov-jdk14
Maven/org.bouncycastle:bcprov-jdk15to18
Introduced in: 1.74Fixed in: 1.84
Fix# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcprov-jdk15to18
Maven/org.bouncycastle:bcprov-jdk18on
Introduced in: 1.74Fixed in: 1.84
Fix# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcprov-jdk18on

References