An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Karaf
Subscribe
|
|
Bouncycastle
Subscribe
|
Bc-java
Subscribe
|
|
Oracle
Subscribe
|
Banking Corporate Lending Process Management
Subscribe
Banking Credit Facilities Process Management
Subscribe
Banking Extensibility Workbench
Subscribe
Banking Supply Chain Finance
Subscribe
Banking Virtual Account Management
Subscribe
Blockchain Platform
Subscribe
Commerce Guided Search
Subscribe
Communications Application Session Controller
Subscribe
Communications Cloud Native Core Network Slice Selection Function
Subscribe
Communications Convergence
Subscribe
Communications Messaging Server
Subscribe
Communications Pricing Design Center
Subscribe
Communications Session Report Manager
Subscribe
Communications Session Route Manager
Subscribe
Jd Edwards Enterpriseone Tools
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Utilities Framework
Subscribe
Webcenter Portal
Subscribe
|
|
Redhat
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0782 | An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different. |
Github GHSA |
GHSA-73xv-w5gp-frxh | Logic error in Legion of the Bouncy Castle BC Java |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 12 May 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bouncycastle bc-java
|
|
| CPEs | cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.66:*:*:*:*:*:*:* |
cpe:2.3:a:bouncycastle:bc-java:1.65:*:*:*:*:*:*:* cpe:2.3:a:bouncycastle:bc-java:1.66:*:*:*:*:*:*:* |
| Vendors & Products |
Bouncycastle legion-of-the-bouncy-castle-java-crytography-api
|
Bouncycastle bc-java
|
Mon, 25 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:33:56.942Z
Reserved: 2020-11-02T00:00:00
Link: CVE-2020-28052
No data.
Status : Modified
Published: 2020-12-18T01:15:12.587
Modified: 2025-05-12T17:37:16.527
Link: CVE-2020-28052
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA