bcprov-jdk18on is vulnerable to Inadequate Encryption Strength
71
High Risk
BKS keystore loading still accepts a legacy store version that uses a 16-bit integrity MAC key. That truncated MAC key makes integrity protection of the keystore substantially weaker than modern BKS versions. An attacker who can modify a legacy-format keystore may bypass integrity detection more easily. The fix rejects or hardens the legacy 16-bit MAC-key BKS version.
You are affected if you are using a version that falls within the vulnerable range and you load legacy BKS v0/v1 keystores.
bcprov-jdk18on is vulnerable to Inadequate Encryption Strength in versions 0.0.1 - 1.84.0.
Upgrade the org.bouncycastle provider library for your JDK target (bcprov-jdk18on, bcprov-jdk15to18 or bcprov-jdk14) to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant