bcpkix-jdk18on is vulnerable to Uncontrolled Resource Consumption
69
Medium Risk
The CRMF/CMP password-based MAC builder in the org.bouncycastle.cert.crmf package honours the iteration count declared in incoming protected messages without an upper bound. Processing a crafted CMP message with a very large password-based MAC iteration count forces excessive key-derivation work. Before the fix, untrusted CMP input can drive uncontrolled CPU consumption. The fix bounds the accepted iteration count.
You are affected if you are using a version that falls within the vulnerable range and you process CRMF or CMP messages protected with password-based MAC from untrusted sources.
bcpkix-jdk18on is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 1.84.0.
Upgrade the org.bouncycastle:bcpkix-jdk18on library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant