bcprov-jdk18on is vulnerable to Observable Timing Discrepancy
89
High Risk
A covert timing channel vulnerability exists in Legion of the Bouncy Castle Inc. BC-JAVA core across all core modules. The issue is associated with the FrodoEngine.java component and affects BC-JAVA versions 1.71 through 1.83, fixed in 1.84.
You are affected if you are using a version that falls within the vulnerable range.
bcprov-jdk18on is vulnerable to Observable Timing Discrepancy in versions 1.71 - 1.83.
Upgrade the org.bouncycastle:bcprov-jdk18on library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant