MEDIUM
GHSA-wg6q-6289-32hp
Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules
Quick fix
GHSA-wg6q-6289-32hp — org.bouncycastle:bcpkix-jdk18on: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcpkix-jdk18onDetails
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules).
PKIX draft CompositeVerifier accepts empty signature sequence as valid.
This issue affects BC-JAVA: from 1.49 before 1.84.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.bouncycastle:bcpkix-jdk18on
Introduced in:
1.49Fixed in: 1.84Fix
# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcpkix-jdk18onMaven/org.bouncycastle:bcpkix-jdk15to18
Introduced in:
1.49Fixed in: 1.84Fix
# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcpkix-jdk15to18Maven/org.bouncycastle:bcpkix-jdk15on
Introduced in:
1.49Fixed in: 1.84Fix
# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcpkix-jdk15onMaven/org.bouncycastle:bcpkix-jdk14
Introduced in:
1.49Fixed in: 1.84Fix
# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcpkix-jdk14Maven/org.bouncycastle:bcpkix-debug-jdk18on
Introduced in:
1.49Fixed in: 1.84Fix
# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcpkix-debug-jdk18onMaven/org.bouncycastle:bcpkix-debug-jdk15to18
Introduced in:
1.49Fixed in: 1.84Fix
# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcpkix-debug-jdk15to18Maven/org.bouncycastle:bcpkix-debug-jdk14
Introduced in:
1.49Fixed in: 1.84Fix
# pom.xml: bump <version>1.84</version> for org.bouncycastle:bcpkix-debug-jdk14