Description
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0782 | An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different. |
Github GHSA |
GHSA-73xv-w5gp-frxh | Logic error in Legion of the Bouncy Castle BC Java |
References
History
Mon, 12 May 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bouncycastle bc-java
|
|
| CPEs | cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.66:*:*:*:*:*:*:* |
cpe:2.3:a:bouncycastle:bc-java:1.65:*:*:*:*:*:*:* cpe:2.3:a:bouncycastle:bc-java:1.66:*:*:*:*:*:*:* |
| Vendors & Products |
Bouncycastle legion-of-the-bouncy-castle-java-crytography-api
|
Bouncycastle bc-java
|
Mon, 25 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Subscriptions
Apache
Subscribe
Karaf
Subscribe
Bouncycastle
Subscribe
Bc-java
Subscribe
Oracle
Subscribe
Banking Corporate Lending Process Management
Subscribe
Banking Credit Facilities Process Management
Subscribe
Banking Extensibility Workbench
Subscribe
Banking Supply Chain Finance
Subscribe
Banking Virtual Account Management
Subscribe
Blockchain Platform
Subscribe
Commerce Guided Search
Subscribe
Communications Application Session Controller
Subscribe
Communications Cloud Native Core Network Slice Selection Function
Subscribe
Communications Convergence
Subscribe
Communications Messaging Server
Subscribe
Communications Pricing Design Center
Subscribe
Communications Session Report Manager
Subscribe
Communications Session Route Manager
Subscribe
Jd Edwards Enterpriseone Tools
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Utilities Framework
Subscribe
Webcenter Portal
Subscribe
Redhat
Subscribe
Camel Quarkus
Subscribe
Integration
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Application Platform Eus
Subscribe
Jboss Fuse
Subscribe
Jbosseapxp
Subscribe
Red Hat Single Sign On
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:33:56.942Z
Reserved: 2020-11-02T00:00:00.000Z
Link: CVE-2020-28052
No data.
Status : Modified
Published: 2020-12-18T01:15:12.587
Modified: 2025-05-12T17:37:16.527
Link: CVE-2020-28052
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA