VDB

DEBIAN-CVE-2020-28052

DEBIAN-CVE-2020-28052 PUBLISHED CVSS 8.100000381469727 HIGH

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

Risk Scores

CVSS 3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:14bouncycastle0, 0, 0
Debian:11bouncycastle0, 0, 0
Debian:13bouncycastle0, 0, 0
Debian:12bouncycastle0, 0, 0

Timeline

  • Dec 18, 2020 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›