bcprov-jdk18on is vulnerable to Improper Verification of Cryptographic Signature
87
High Risk
RSADigestSigner on the PKCS#1 NULL-omitted DigestInfo path compares the recovered digest while skipping the last two hash bytes. Signatures that mismatch only in those trailing bytes can still verify successfully. Callers that accept RSA PKCS#1 signatures through this path may treat forged or mutated signatures as valid. The fix compares the full digest including the final two bytes.
You are affected if you are using a version that falls within the vulnerable range and you verify RSA PKCS#1 signatures through RSADigestSigner on the NULL-omitted DigestInfo path.
bcprov-jdk18on is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.1 - 1.84.0.
Upgrade the org.bouncycastle provider library for your JDK target (bcprov-jdk18on, bcprov-jdk15to18 or bcprov-jdk14) to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant