bcprov-jdk18on is vulnerable to Allocation of Resources Without Limits or Throttling
53
Medium Risk
Loading a BCFKS keystore honours KDF iteration/cost parameters taken from the keystore file without an upper bound. A crafted BCFKS file can demand extreme KDF work during load. Applications that open untrusted BCFKS keystores can be stalled or exhausted. The fix caps accepted KDF cost parameters when loading BCFKS files.
You are affected if you are using a version that falls within the vulnerable range and you load BCFKS keystores from untrusted files.
bcprov-jdk18on is vulnerable to Allocation of Resources Without Limits or Throttling in versions 0.0.1 - 1.84.0.
Upgrade the org.bouncycastle provider library for your JDK target (bcprov-jdk18on, bcprov-jdk15to18 or bcprov-jdk14) to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant