2.0.0
4 years ago
5 months ago
Known vulnerabilities in the org.bouncycastle:bc-fips-debug package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Uncontrolled Resource Consumption ('Resource Exhaustion') within the How to fix Uncontrolled Resource Consumption ('Resource Exhaustion')? Upgrade | [,1.0.2.4) |
Affected versions of this package are vulnerable to Improper Authentication. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules, where it is possible for temporary keys used by the module to be zeroed out while still in use by the module. Notes:
The issue can be exploited when the JVM is stressed for memory. As the vulnerability requires harder to achieve means of exploitation, we marked the Attack Complexity with High. There is no clear specification that the attacker needs to have local access. How to fix Improper Authentication? Upgrade | [,1.0.2.4) |