VDB
DEBIAN-CVE-2023-33201
DEBIAN-CVE-2023-33201
PUBLISHED
CVSS 5.300000190734863 MEDIUM
Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | bouncycastle | 1.72-2, 1.77-1, 1.80-1 |
| Debian:14 | bouncycastle | 0, 0, 0 |
| Debian:13 | bouncycastle | 0, 0, 0 |
| Debian:11 | bouncycastle | 1.80-3, 0, 1.68-2 |
Exploit Intelligence
- releasenotes.html (github-poc)
- druid-612f0710.json (github-poc)
Timeline
- Jul 5, 2023 CVE Published
- Apr 28, 2026 CVE Updated