bcpkix-jdk18on is vulnerable to Improper Verification of Cryptographic Signature
87
High Risk
The CMSSignedData verification logic treats a SignedData structure that contains no signers as successfully verified. Code that relies on signature verification to confirm authenticity accepts content that carries zero signatures. Before the fix, unsigned or signer-stripped messages can be mistaken for validly signed data. The fix rejects SignedData that contains no signer information.
You are affected if you are using a version that falls within the vulnerable range and you rely on CMS SignedData signature verification to authenticate externally supplied messages.
bcpkix-jdk18on is vulnerable to Improper Verification of Cryptographic Signature in versions 0.0.1 - 1.84.0.
Upgrade the org.bouncycastle:bcpkix-jdk18on library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant