Description
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Published: 2018-06-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-4233-1 bouncycastle security update
EUVD EUVD EUVD-2018-0718 Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator
Github GHSA Github GHSA GHSA-xqj7-j8j5-f2xr Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator
History

Mon, 12 May 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Bouncycastle bc-java
CPEs cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:*:*:*:*:*:*:*:* cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:*
Vendors & Products Bouncycastle legion-of-the-bouncy-castle-java-crytography-api
Bouncycastle bc-java

Fri, 23 Aug 2024 05:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:7::el7 cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7

Subscriptions

Bouncycastle Bc-java Fips Java Api
Debian Debian Linux
Netapp Oncommand Workflow Automation
Oracle Api Gateway Business Process Management Suite Business Transaction Management Communications Application Session Controller Communications Converged Application Server Communications Webrtc Session Controller Enterprise Repository Managed File Transfer Peoplesoft Enterprise Peopletools Retail Convenience And Fuel Pos Software Retail Xstore Point Of Service Soa Suite Webcenter Portal Weblogic Server
Redhat Enterprise Linux Jboss Enterprise Application Platform Jboss Fuse Jboss Single Sign On Openshift Application Runtimes Virtualization
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T12:33:49.372Z

Reserved: 2018-04-30T00:00:00.000Z

Link: CVE-2018-1000180

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-05T13:29:00.203

Modified: 2025-05-12T17:37:16.527

Link: CVE-2018-1000180

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-04-18T00:00:00Z

Links: CVE-2018-1000180 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses