CVE-2020-28052 REJECTED

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

EPSS 4.10% · 88.5th percentile

Risk Scores

EPSS Score
4.10%
88.5th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSbouncycastle0, 1.68-5, 1.68-4
Ubuntu:20.04:LTSbouncycastle0, 1.61-1
Ubuntu:16.04:LTSbouncycastle0, 1.49+dfsg-3ubuntu1, 1.51-4ubuntu1
Ubuntu:24.04:LTSbouncycastle0, 1.77-1, 1.72-2
Ubuntu:25.10bouncycastle1.80-3, 0, 1.77-1
Ubuntu:18.04:LTSbouncycastle1.58-1, 1.59-1, 0

Timeline

References

Open in Interactive Console →