Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Bouncycastle
Subscribe
|
Bc-java
Subscribe
|
|
Netapp
Subscribe
|
Oncommand Workflow Automation
Subscribe
|
|
Opensuse
Subscribe
|
Leap
Subscribe
|
|
Oracle
Subscribe
|
Api Gateway
Subscribe
Banking Platform
Subscribe
Business Process Management Suite
Subscribe
Business Transaction Management
Subscribe
Communications Application Session Controller
Subscribe
Communications Converged Application Server
Subscribe
Communications Convergence
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Webrtc Session Controller
Subscribe
Data Integrator
Subscribe
Enterprise Manager Base Platform
Subscribe
Enterprise Manager For Fusion Middleware
Subscribe
Enterprise Repository
Subscribe
Managed File Transfer
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Retail Convenience And Fuel Pos Software
Subscribe
Retail Xstore Point Of Service
Subscribe
Soa Suite
Subscribe
Utilities Network Management System
Subscribe
Webcenter Portal
Subscribe
Weblogic Server
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4446-656p-f54g | Deserialization of Untrusted Data in Bouncy castle |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 12 May 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bouncycastle bc-java
|
|
| CPEs | cpe:2.3:a:bouncycastle:bc-java:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Bouncycastle legion-of-the-bouncy-castle-java-crytography-api
|
Bouncycastle bc-java
|
Thu, 14 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-14T20:37:00.531Z
Reserved: 2018-06-29T00:00:00
Link: CVE-2018-1000613
Updated: 2024-08-05T12:40:47.584Z
Status : Modified
Published: 2018-07-09T20:29:00.283
Modified: 2025-05-12T17:37:16.527
Link: CVE-2018-1000613
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA