Back

MEDIUM

bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack)

Published May 9, 2024

Description

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

Weaknesses (2)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 9, 2024
Updated Aug 19, 2024
Reserved Mar 24, 2024
CISA Vulnrichment
Updated Aug 19, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 18, 2024
GHSA-V435-XC8X-WVR9