CVE-2024-30171

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
Configurations

No configuration.

History

21 Nov 2024, 09:11

Type Values Removed Values Added
References () https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9030171 - () https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9030171 -
References () https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9030171 - () https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9030171 -
References () https://security.netapp.com/advisory/ntap-20240614-0008/ - () https://security.netapp.com/advisory/ntap-20240614-0008/ -
References () https://www.bouncycastle.org/latest_releases.html - () https://www.bouncycastle.org/latest_releases.html -

19 Aug 2024, 18:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
CWE CWE-203

14 Jun 2024, 13:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240614-0008/ -
Summary
  • (es) Se descubrió un problema en la API TLS Java de Bouncy Castle y en el proveedor JSSE anterior a la versión 1.78. Es posible que se produzcan fugas basadas en el tiempo en los protocolos de enlace basados en RSA debido al procesamiento de excepciones.

14 May 2024, 15:21

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 15:21

Updated : 2024-11-21 09:11


NVD link : CVE-2024-30171

Mitre link : CVE-2024-30171

CVE.ORG link : CVE-2024-30171


JSON object : View

Products Affected

No product.

CWE
CWE-203

Observable Discrepancy