Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
-
None
Description
For Bouncy Castle for java before 1.74(excluding), it was discovered that there was a potential LDAP injection. During the certificate validation process, bouncycastle used the certificate's "Subject Name" into an LDAP search filter without any escaping.
Attachments
Issue Links
- links to