SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-33201

Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability.

MEDIUM 5.3EPSS 0.77%

Does this matter?

Lower severity and a low EPSS score (0.77%). Track it; it rarely justifies an emergency change on its own.

Description

Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.77% probability · 54th percentile
CISA KEV
Not listed
Weakness
CWE-295
Affected
bouncycastle/bc-java
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.