原始 OSV JSON{
"id": "GHSA-73xv-w5gp-frxh",
"aliases": [
"CVE-2020-28052"
],
"details": "An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.",
"summary": "Logic error in Legion of the Bouncy Castle BC Java",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.65"
},
{
"fixed": "1.67"
}
]
}
],
"package": {
"name": "org.bouncycastle:bcprov-jdk15to18",
"ecosystem": "Maven"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.65"
},
{
"fixed": "1.67"
}
]
}
],
"package": {
"name": "org.bouncycastle:bcprov-jdk15",
"ecosystem": "Maven"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.65"
},
{
"fixed": "1.67"
}
]
}
],
"package": {
"name": "org.bouncycastle:bcprov-jdk15on",
"ecosystem": "Maven"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.65"
},
{
"fixed": "1.67"
}
]
}
],
"package": {
"name": "org.bouncycastle:bcprov-ext-jdk15on",
"ecosystem": "Maven"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.65"
},
{
"fixed": "1.67"
}
]
}
],
"package": {
"name": "org.bouncycastle:bcprov-jdk14",
"ecosystem": "Maven"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.65"
},
{
"fixed": "1.67"
}
]
}
],
"package": {
"name": "org.bouncycastle:bcprov-jdk16",
"ecosystem": "Maven"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.65"
},
{
"fixed": "1.67"
}
]
}
],
"package": {
"name": "org.bouncycastle:bcprov-ext-jdk16",
"ecosystem": "Maven"
}
}
],
"modified": "2022-02-08T22:01:10Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"published": "2021-04-30T16:14:15Z",
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28052",
"type": "ADVISORY"
},
{
"url": "https://github.com/bcgit/bc-java/commit/97578f9b7ed277e6ecb58834e85e3d18385a4219",
"type": "WEB"
},
{
"url": "https://www.synopsys.com/blogs/software-security/cve-2020-28052-bouncy-castle",
"type": "WEB"
},
{
"url": "https://www.oracle.com/security-alerts/cpuoct2021.html",
"type": "WEB"
},
{
"url": "https://www.oracle.com/security-alerts/cpujul2022.html",
"type": "WEB"
},
{
"url": "https://www.oracle.com/security-alerts/cpujan2022.html",
"type": "WEB"
},
{
"url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
"type": "WEB"
},
{
"url": "https://www.oracle.com/security-alerts/cpuApr2021.html",
"type": "WEB"
},
{
"url": "https://www.oracle.com//security-alerts/cpujul2021.html",
"type": "WEB"
},
{
"url": "https://www.bouncycastle.org/releasenotes.html",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/rfc0db1f3c375087e69a239f9284ded72d04fbb55849eadde58fa9dc2@%3Cissues.karaf.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/rf9abfc0223747a56694825c050cc6b66627a293a32ea926b3de22402@%3Cissues.karaf.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/rdfd2901b8b697a3f6e2c9c6ecc688fd90d7f881937affb5144d61d6e@%3Ccommits.druid.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/rddd2237b8636a48d573869006ee809262525efb2b6ffa6eff50d2a2d@%3Cjira.kafka.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/rdcbad6d8ce72c79827ed8c635f9a62dd919bb21c94a0b64cab2efc31@%3Cissues.karaf.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/rcd37d9214b08067a2e8f2b5b4fd123a1f8cb6008698d11ef44028c21@%3Cissues.karaf.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/rc9e441c1576bdc4375d32526d5cf457226928e9c87b9f54ded26271c@%3Cissues.karaf.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/r954d80fd18e9dafef6e813963eb7e08c228151c2b6268ecd63b35d1f@%3Ccommits.druid.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/r8c36ba34e80e05eecb1f80071cc834d705616f315b634ec0c7d8f42e@%3Cissues.solr.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/r77af3ac7c3bfbd5454546e13faf7aec21d627bdcf36c9ca240436b94@%3Cissues.karaf.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/r4e1619cfefcd031fac62064a3858f5c9229eef907bd5d8ef14c594fc@%3Cissues.karaf.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/r37d332c0bf772f4982d1fdeeb2f88dd71dab6451213e69e43734eadc@%3Ccommits.pulsar.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/r30a139c165b3da6e0d5536434ab1550534011b1fdfcd2f5d95892c5b@%3Cissues.karaf.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/r2ddabd06d94b60cfb0141e4abb23201c628ab925e30742f61a04d013@%3Cissues.karaf.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/r25d53acd06f29244b8a103781b0339c5e7efee9099a4d52f0c230e4a@%3Ccommits.druid.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/r175f5a25d100dbe2b1bd3459b3ce882a84c3ff91b120ed4ff2d57b53@%3Ccommits.pulsar.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/r167dbc42ef7c59802c2ca1ac14735ef9cf687c25208229993d6206fe@%3Cissues.karaf.apache.org%3E",
"type": "WEB"
},
{
"url": "https://github.com/bcgit/bc-java/wiki/CVE-2020-28052",
"type": "WEB"
},
{
"url": "https://github.com/bcgit/bc-java",
"type": "PACKAGE"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-670"
],
"severity": "HIGH",
"github_reviewed": true,
"nvd_published_at": "2020-12-18T01:15:00Z",
"github_reviewed_at": "2021-03-19T00:15:55Z"
}
}