bcpkix-jdk18on is vulnerable to Improper Validation of Integrity Check Value
87
High Risk
The CMS API in the org.bouncycastle.cms package does not enforce the authentication tag length when decrypting AuthEnvelopedData content. Authenticated-encrypted content can be processed with a truncated or manipulated AEAD tag, so the integrity check that should reject tampered data can pass. Before the fix, this allows undetected modification or forgery of authenticated CMS content. The fix validates the expected tag length and rejects mismatches.
You are affected if you are using a version that falls within the vulnerable range and you decrypt CMS AuthEnvelopedData messages from untrusted or externally influenced sources.
bcpkix-jdk18on is vulnerable to Improper Validation of Integrity Check Value in versions 0.0.1 - 1.84.0.
Upgrade the org.bouncycastle:bcpkix-jdk18on library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant