Skip to content

[GHSA-p93r-85wp-75v3] Bouncy Castle Has Covert Timing Channel Vulnerability#7804

Open
jmini wants to merge 1 commit into
jmini/advisory-improvement-7804from
jmini-GHSA-p93r-85wp-75v3
Open

[GHSA-p93r-85wp-75v3] Bouncy Castle Has Covert Timing Channel Vulnerability#7804
jmini wants to merge 1 commit into
jmini/advisory-improvement-7804from
jmini-GHSA-p93r-85wp-75v3

Conversation

@jmini
Copy link
Copy Markdown

@jmini jmini commented May 22, 2026

Updates

  • Modification of the ranges to indicate the additional fixed versions 1.80.2 and 1.81.1.
  • CVSS v4 --> Not intended
  • Description
  • Severity --> Not intended

Comments
As indicated on the wiki page https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905598 additional releases for pkg:maven/org.bouncycastle/bcprov-jdk18on with the fix were created on 2026-05-15

@github-actions github-actions Bot changed the base branch from main to jmini/advisory-improvement-7804 May 22, 2026 17:15
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/S:P/AU:Y/U:Red"
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"
Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This change in the score is not intended, it is due to a bug in the editor, see #5357

Suggested change
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N"
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/S:P/AU:Y/U:Red"

"CWE-385"
],
"severity": "HIGH",
"severity": "CRITICAL",
Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is also not intended.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant