bcpkix-jdk15to18 is vulnerable to Uncontrolled Resource Consumption
69
Medium Risk
The CMP/CRMF password-based MAC builder derives its MAC key by running a hash-iteration loop whose count is taken directly from the incoming protected message. That count is not bounded, so an externally supplied CMP message can request an arbitrarily large iteration count. Processing such a message forces the library into a very long hashing loop, exhausting processing resources and denying service on the certificate-management endpoint. The fix caps the accepted iteration count and rejects messages that exceed it.
You are affected if you are using a version that falls within the vulnerable range.
bcpkix-jdk15to18 is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 1.84.0.
Upgrade the org.bouncycastle:bcpkix-jdk15to18 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant