bcprov-jdk18on is vulnerable to Improper Certificate Validation
93
Critical Risk
ProvOcspRevocationChecker accepts a stapled OCSP response without verifying that the response is bound to the certificate under check. An OCSP response for a different certificate can be presented and treated as evidence of status for the wrong cert. TLS or PKIX flows that rely on stapled OCSP may accept revoked or unrelated status information. The fix requires the OCSP response to match the certificate being validated.
You are affected if you are using a version that falls within the vulnerable range and you use stapled OCSP via ProvOcspRevocationChecker.
bcprov-jdk18on is vulnerable to Improper Certificate Validation in versions 1.66.0 - 1.84.0.
Upgrade the org.bouncycastle:bcprov-jdk18on and/or the org.bouncycastle:bcprov-jdk15to18 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant