bcprov-jdk18on is vulnerable to Improper Validation of Integrity Check Value
87
High Risk
IESEngine in stream mode derives MAC and cipher keying material with a length-dependent KDF split that an attacker can influence through ciphertext framing. By adjusting lengths, forged stream-mode IES payloads can be constructed so the MAC still verifies. Integrity of IES-protected messages is undermined for the stream-mode path. The fix makes the KDF split independent of attacker-controlled length framing.
You are affected if you are using a version that falls within the vulnerable range and you use stream-mode IESEngine to decrypt or verify IES messages.
bcprov-jdk18on is vulnerable to Improper Validation of Integrity Check Value in versions 0.0.1 - 1.84.0.
Upgrade the org.bouncycastle provider library for your JDK target (bcprov-jdk18on, bcprov-jdk15to18 or bcprov-jdk14) to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant