VDB
RHSA-2021%3A1401
RHSA-2021%3A1401
PUBLISHED
CVSS 5.900000095367432 MEDIUM
A flaw was found in bouncycastle. A timing issue within the EC math library can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.
Risk Scores
CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Fuse 7.8.1 |
Timeline
- Apr 27, 2021 CVE Published
- Apr 2, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:1401 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/documentation/en-us/red_hat_fuse/7.8/html/installing_on_apache_karaf/apply-hotfix-patch advisory
- https://access.redhat.com/documentation/en-us/red_hat_fuse/7.8/html/deploying_into_spring_boot/patch-red-hat-fuse-applications advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=jboss.fuse&downloadType=distributions&version=7.8.0 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1912881 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_1401.json advisory
- https://access.redhat.com/security/cve/CVE-2020-15522 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1962879 issue
- https://www.cve.org/CVERecord?id=CVE-2020-15522 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-15522 advisory
- https://access.redhat.com/security/cve/CVE-2020-28052 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-28052 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-28052 advisory