VulnerabilityModified
CVE-2023-33201
Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability.
MEDIUM 5.3EPSS 0.77%
Does this matter?
Lower severity and a low EPSS score (0.77%). Track it; it rarely justifies an emergency change on its own.
Description
Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.77% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- bouncycastle/bc-java
- Source
- cve@mitre.org
References
- https://bouncycastle.orgProduct
- https://github.com/bcgit/bc-java/commit/e8c409a8389c815ea3fda5e8b94c92fdfe583bccPatch
- https://github.com/bcgit/bc-java/wiki/CVE-2023-33201Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00000.html
- https://security.netapp.com/advisory/ntap-20230824-0008/
- https://bouncycastle.orgProduct
- https://github.com/bcgit/bc-java/commit/e8c409a8389c815ea3fda5e8b94c92fdfe583bccPatch
- https://github.com/bcgit/bc-java/wiki/CVE-2023-33201Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00000.html
- https://security.netapp.com/advisory/ntap-20230824-0008/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.