Back

HIGH

bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible

Published Dec 18, 2020

Description

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

Affected products

Remediation

Red Hat mitigation

Users unable to upgrade to version 1.67 or greater can copy the `OpenBSDBCrypt.doCheckPassword()` method implementation (https://github.com/bcgit/bc-java/blob/r1rv67/core/src/main/java/org/bouncycastle/crypto/generators/OpenBSDBCrypt.java#L259-L343) into their own utility class and supplement it with the required methods and variables as required

References (50)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 18, 2020
Updated Aug 4, 2024
Reserved Nov 2, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 18, 2020
ENISA EUVD
Assigner mitre
Published Dec 18, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2021-0782 GHSA-73XV-W5GP-FRXH