Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.

Project Subscriptions

Vendors Products
Bouncycastle Subscribe
Bc-java Subscribe
Fips Java Api Subscribe
Debian Linux Subscribe
Oncommand Workflow Automation Subscribe
Api Gateway Subscribe
Business Process Management Suite Subscribe
Business Transaction Management Subscribe
Communications Application Session Controller Subscribe
Communications Converged Application Server Subscribe
Communications Webrtc Session Controller Subscribe
Enterprise Repository Subscribe
Managed File Transfer Subscribe
Peoplesoft Enterprise Peopletools Subscribe
Retail Convenience And Fuel Pos Software Subscribe
Retail Xstore Point Of Service Subscribe
Soa Suite Subscribe
Webcenter Portal Subscribe
Weblogic Server Subscribe
Enterprise Linux Subscribe
Jboss Enterprise Application Platform Subscribe
Jboss Fuse Subscribe
Jboss Single Sign On Subscribe
Openshift Application Runtimes Subscribe
Virtualization Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-4233-1 bouncycastle security update
EUVD EUVD EUVD-2018-0718 Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator
Github GHSA Github GHSA GHSA-xqj7-j8j5-f2xr Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 12 May 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Bouncycastle bc-java
CPEs cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:*:*:*:*:*:*:*:* cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:*
Vendors & Products Bouncycastle legion-of-the-bouncy-castle-java-crytography-api
Bouncycastle bc-java

Fri, 23 Aug 2024 05:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:7::el7 cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T12:33:49.372Z

Reserved: 2018-04-30T00:00:00

Link: CVE-2018-1000180

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-05T13:29:00.203

Modified: 2025-05-12T17:37:16.527

Link: CVE-2018-1000180

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-04-18T00:00:00Z

Links: CVE-2018-1000180 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses