Uploaded image for project: 'Cassandra'
  1. Cassandra
  2. CASSANDRA-18723

bcprov-jdk15on-1.70.jar vulnerability: CVE-2023-33201

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Normal
    • Resolution: Fixed
    • 5.0-alpha1, 5.0
    • Dependencies
    • None
    • Security - Privilege Escalation
    • Normal
    • Normal
    • User Report
    • All
    • None
    • Hide

      run dependency-check

      Show
      run dependency-check

    Description

      https://nvd.nist.gov/vuln/detail/CVE-2023-33201

      Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.

      Attachments

        Issue Links

          Activity

            People

              brandon.williams Brandon Williams
              brandon.williams Brandon Williams
              Brandon Williams
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: