bcpkix-jdk18on is vulnerable to Improper Validation of Integrity Check Value
87
High Risk
When CMS AuthenticatedData carries authenticated attributes, the MAC is verified over the attributes but the protected content itself is not bound to the MAC. This lets the content be replaced while the MAC still validates successfully. Before the fix, the integrity of authenticated content is not guaranteed when authenticated attributes are present. The fix binds the content to the MAC verification.
You are affected if you are using a version that falls within the vulnerable range and you process CMS AuthenticatedData messages with authenticated attributes from untrusted sources.
bcpkix-jdk18on is vulnerable to Improper Validation of Integrity Check Value in versions 0.0.1 - 1.84.0.
Upgrade the org.bouncycastle:bcpkix-jdk18on library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant