VDB
BDU%3A2023-07367
BDU%3A2023-07367
PUBLISHED
CVSS 7.099999904632568 HIGH
Уязвимость библиотеки проверки ключа EC модуля Math средств криптографической защиты Bouncy Castle, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Risk Scores
CVSS 2.0
7.099999904632568
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Legion of the Bouncy Castle Inc., NetApp Inc., Elastic NV | Bouncy Castle, Bouncy Castle FIPS Java API (BC-FJA), Bouncy Castle Crypto Package For Java, Bouncy Castle Cryptography Library For .NET, Bouncy Castle FIPS .NET API (BC-FNA), Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Oncommand Insight, SANtricity Storage Plugin for vCenter, SnapCenter, Elasticsearch |
Timeline
- Nov 1, 2023 CVE Published
References
- https://github.com/bcgit/bc-csharp/wiki/CVE-2020-15522 url
- https://github.com/bcgit/bc-java/wiki/CVE-2020-15522 url
- https://security.netapp.com/advisory/ntap-20210622-0007/ url
- https://www.bouncycastle.org/releasenotes.html url
- https://discuss.elastic.co/t/cves-present-in-the-latest-version/332950 url
- https://jvndb.jvn.jp/ja/contents/2020/JVNDB-2020-015754.html url
- https://bugzilla.redhat.com/show_bug.cgi?id=1962879 url
- https://github.com/bcgit/bc-csharp/releases/tag/release-1.8.7 advisory
- https://github.com/bcgit/bc-java/releases/tag/r1rv66 advisory
- https://github.com/elastic/elasticsearch/releases advisory