ZeroHour

CVE-2020-28052

PoC
CVSS 3.1
8.1 high
EPSS
7%p94
Published
()
Modified
Description

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.

Vendors
bouncycastleapacheoracle
Products
bc-java, karaf, banking corporate lending process management, banking credit facilities process management, banking extensibility workbench, banking supply chain finance, banking virtual account management, blockchain platform, commerce guided search, communications application session controller, communications cloud native core network slice selection function, communications convergence
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news