VDB

DEBIAN-CVE-2023-33201

DEBIAN-CVE-2023-33201 PUBLISHED CVSS 5.300000190734863 MEDIUM

Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
Debian:12bouncycastle1.72-2, 1.77-1, 1.80-1
Debian:14bouncycastle0, 0, 0
Debian:13bouncycastle0, 0, 0
Debian:11bouncycastle1.80-3, 0, 1.68-2

Exploit Intelligence

Timeline

  • Jul 5, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›