CVE-2020-28052
published 2020-12-18CVE-2020-28052: An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when…
PriorityP355high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
7.14%
93.6th percentile
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | karaf | — | — |
| bouncycastle | bc-java | — | — |
| bouncycastle | bc-java | — | — |
| debian | bouncycastle | < bouncycastle 1.65-2 (bookworm) | bouncycastle 1.65-2 (bookworm) |
| oracle | banking_corporate_lending_process_management | — | — |
| oracle | banking_corporate_lending_process_management | — | — |
| oracle | banking_corporate_lending_process_management | — | — |
| oracle | banking_credit_facilities_process_management | — | — |
| oracle | banking_credit_facilities_process_management | — | — |
| oracle | banking_credit_facilities_process_management | — | — |
| oracle | banking_extensibility_workbench | — | — |
| oracle | banking_extensibility_workbench | — | — |
| oracle | banking_extensibility_workbench | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | banking_supply_chain_finance | — | — |
| oracle | banking_virtual_account_management | — | — |
| oracle | banking_virtual_account_management | — | — |
| oracle | banking_virtual_account_management | — | — |
| oracle | blockchain_platform | < 21.1.2 | 21.1.2 |
| oracle | commerce_guided_search | — | — |
| oracle | communications_application_session_controller | — | — |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| oracle | communications_convergence | — | — |
| oracle | communications_messaging_server | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_oracle9.8HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Logic error in Legion of the Bouncy Castle BC Java
ghsa·2021-04-30
CVE-2020-28052 [HIGH] CWE-670 Logic error in Legion of the Bouncy Castle BC Java
Logic error in Legion of the Bouncy Castle BC Java
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
OSV
Logic error in Legion of the Bouncy Castle BC Java
osv·2021-04-30
CVE-2020-28052 [HIGH] Logic error in Legion of the Bouncy Castle BC Java
Logic error in Legion of the Bouncy Castle BC Java
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
OSV
CVE-2020-28052: An issue was discovered in Legion of the Bouncy Castle BC Java 1
osv·2020-12-18·CVSS 8.1
CVE-2020-28052 [HIGH] CVE-2020-28052: An issue was discovered in Legion of the Bouncy Castle BC Java 1
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Web General (Bouncy Castle Java Library) — CVE-2020-28052
vendor_oracle·2023-04-15·CVSS 8.1
CVE-2020-28052 [HIGH] Oracle Oracle Analytics Risk Matrix: Analytics Web General (Bouncy Castle Java Library) — CVE-2020-28052
Oracle Oracle Analytics Risk Matrix: Analytics Web General (Bouncy Castle Java Library) vulnerability
CVE: CVE-2020-28052
CVSS: 8.1
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Installer (Bouncy Castle Java Library) — CVE-2020-28052
vendor_oracle·2022-10-15·CVSS 8.1
CVE-2020-28052 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Installer (Bouncy Castle Java Library) — CVE-2020-28052
Oracle Oracle Fusion Middleware Risk Matrix: Installer (Bouncy Castle Java Library) vulnerability
CVE: CVE-2020-28052
CVSS: 8.1
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (Bouncy Castle Java Library) — CVE-2020-28052
vendor_oracle·2022-07-15·CVSS 8.1
CVE-2020-28052 [HIGH] Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (Bouncy Castle Java Library) — CVE-2020-28052
Oracle Oracle Commerce Risk Matrix: Framework, Experience Manager (Bouncy Castle Java Library) vulnerability
CVE: CVE-2020-28052
CVSS: 8.1
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Bouncy Castle Java Library) — CVE-2020-28052
vendor_oracle·2022-04-15·CVSS 8.1
CVE-2020-28052 [HIGH] Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Bouncy Castle Java Library) — CVE-2020-28052
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Bouncy Castle Java Library) vulnerability
CVE: CVE-2020-28052
CVSS: 8.1
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Messaging (Bouncy Castle Java Library) — CVE-2020-28052
vendor_oracle·2022-01-15·CVSS 8.1
CVE-2020-28052 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Messaging (Bouncy Castle Java Library) — CVE-2020-28052
Oracle Oracle Communications Applications Risk Matrix: Messaging (Bouncy Castle Java Library) vulnerability
CVE: CVE-2020-28052
CVSS: 8.1
Protocol: S/MIME
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Reports (Bouncy Castle Java Library) — CVE-2020-28052
vendor_oracle·2021-10-15·CVSS 8.1
CVE-2020-28052 [HIGH] Oracle Oracle Communications Risk Matrix: Reports (Bouncy Castle Java Library) — CVE-2020-28052
Oracle Oracle Communications Risk Matrix: Reports (Bouncy Castle Java Library) vulnerability
CVE: CVE-2020-28052
CVSS: 8.1
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (Bouncy Castle Java Library) — CVE-2020-28052
vendor_oracle·2021-07-15·CVSS 9.8
CVE-2020-28052 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (Bouncy Castle Java Library) — CVE-2020-28052
Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (Bouncy Castle Java Library) vulnerability
CVE: CVE-2020-28052
CVSS: 9.8
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Message Store (Bouncy Castle Java Library) — CVE-2020-28052
vendor_oracle·2021-04-15·CVSS 9.8
CVE-2020-28052 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Message Store (Bouncy Castle Java Library) — CVE-2020-28052
Oracle Oracle Communications Applications Risk Matrix: Message Store (Bouncy Castle Java Library) vulnerability
CVE: CVE-2020-28052
CVSS: 9.8
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Red Hat
bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible
vendor_redhat·2020-12-18·CVSS 8.1
CVE-2020-28052 [HIGH] CWE-287 bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible
bouncycastle: password bypass in OpenBSDBCrypt.checkPassword utility possible
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
A flaw was found in bouncycastle. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password allowing incorrect passwords to indicate they were matching with previously hashed ones that were different. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Mitigation: Users unable to upgrade to version 1.67 or greater can copy the
Debian
CVE-2020-28052: bouncycastle - An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. Th...
vendor_debian·2020·CVSS 8.1
CVE-2020-28052 [HIGH] CVE-2020-28052: bouncycastle - An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. Th...
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
Scope: local
bookworm: resolved (fixed in 1.65-2)
bullseye: resolved (fixed in 1.65-2)
forky: resolved (fixed in 1.65-2)
sid: resolved (fixed in 1.65-2)
trixie: resolved (fixed in 1.65-2)
No detection rules found.
No public exploits indexed.
arXiv
How well does LLM generate security tests?
arxiv_fulltext·2023-10-03
How well does LLM generate security tests?
How well does LLM generate security tests?
## Abstract
Developers often build software on top of third-party libraries (Libs) to improve programmer productivity and software quality. The libraries may contain vulnerabilities exploitable by hackers to attack the applications (Apps) built on top of them. People refer to such attacks as supply chain attacks, the documented number of which has increased 742% in 2022. People created tools to mitigate such attacks, by scanning the library dependencies of Apps, identifying the usage of vulnerable library versions, and suggesting secure alternatives to vulnerable dependencies. However, recent studies show that many developers do not trust the reports by these tools; they ask for code or evidence to demonstrate how library vulnerabilities lead to
arXiv
Security Review of Ethereum Beacon Clients
arxiv_fulltext·2021-09-23
Security Review of Ethereum Beacon Clients
center
[width=7cm]beacon
empty
1cm
Security Review of Ethereum Beacon Clients
1cm
JP Aumasson -- Taurus, Switzerland -- [email protected],
Denis Kolegov -- Tomsk State University, Russia -- [email protected]
Evangelia Stathopoulou -- University College London, UK -- [email protected]
0.5cm
Version
0.5cm
Supported by the Ethereum Foundation.
center
## Abstract
The beacon chain is the backbone of the Ethereum's evolution
towards a proof-of-stake-based scalable network.
Beacon clients are the applications implementing the services
required to operate the beacon chain, namely validators, beacon
nodes, and slashers.
Security defects in beacon clients could lead to loss of funds,
consensus rules violation, network congestion, and other
inconveniences.
We repo
Checkpoint
21st December – Threat Intelligence Bulletin
blogs_checkpoint·2020-12-21
CVE-2020-7200 21st December – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 21st December – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 21st December, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Additional companies have been breached in the high-profile SolarWinds supply chain attack exposed last week. In addition to several US government agencies , Microsoft has confirmed that it was compromised, but states that no customer information or production services were accessed. The nation-state actors have also
https://github.com/bcgit/bc-java/wiki/CVE-2020-28052https://lists.apache.org/thread.html/r167dbc42ef7c59802c2ca1ac14735ef9cf687c25208229993d6206fe%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/r175f5a25d100dbe2b1bd3459b3ce882a84c3ff91b120ed4ff2d57b53%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r25d53acd06f29244b8a103781b0339c5e7efee9099a4d52f0c230e4a%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r2ddabd06d94b60cfb0141e4abb23201c628ab925e30742f61a04d013%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/r30a139c165b3da6e0d5536434ab1550534011b1fdfcd2f5d95892c5b%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/r37d332c0bf772f4982d1fdeeb2f88dd71dab6451213e69e43734eadc%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r4e1619cfefcd031fac62064a3858f5c9229eef907bd5d8ef14c594fc%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/r77af3ac7c3bfbd5454546e13faf7aec21d627bdcf36c9ca240436b94%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/r8c36ba34e80e05eecb1f80071cc834d705616f315b634ec0c7d8f42e%40%3Cissues.solr.apache.org%3Ehttps://lists.apache.org/thread.html/r954d80fd18e9dafef6e813963eb7e08c228151c2b6268ecd63b35d1f%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rc9e441c1576bdc4375d32526d5cf457226928e9c87b9f54ded26271c%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/rcd37d9214b08067a2e8f2b5b4fd123a1f8cb6008698d11ef44028c21%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/rdcbad6d8ce72c79827ed8c635f9a62dd919bb21c94a0b64cab2efc31%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/rddd2237b8636a48d573869006ee809262525efb2b6ffa6eff50d2a2d%40%3Cjira.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/rdfd2901b8b697a3f6e2c9c6ecc688fd90d7f881937affb5144d61d6e%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rf9abfc0223747a56694825c050cc6b66627a293a32ea926b3de22402%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/rfc0db1f3c375087e69a239f9284ded72d04fbb55849eadde58fa9dc2%40%3Cissues.karaf.apache.org%3Ehttps://www.bouncycastle.org/releasenotes.htmlhttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.synopsys.com/blogs/software-security/cve-2020-28052-bouncy-castle/https://github.com/bcgit/bc-java/wiki/CVE-2020-28052https://lists.apache.org/thread.html/r167dbc42ef7c59802c2ca1ac14735ef9cf687c25208229993d6206fe%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/r175f5a25d100dbe2b1bd3459b3ce882a84c3ff91b120ed4ff2d57b53%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r25d53acd06f29244b8a103781b0339c5e7efee9099a4d52f0c230e4a%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/r2ddabd06d94b60cfb0141e4abb23201c628ab925e30742f61a04d013%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/r30a139c165b3da6e0d5536434ab1550534011b1fdfcd2f5d95892c5b%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/r37d332c0bf772f4982d1fdeeb2f88dd71dab6451213e69e43734eadc%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r4e1619cfefcd031fac62064a3858f5c9229eef907bd5d8ef14c594fc%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/r77af3ac7c3bfbd5454546e13faf7aec21d627bdcf36c9ca240436b94%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/r8c36ba34e80e05eecb1f80071cc834d705616f315b634ec0c7d8f42e%40%3Cissues.solr.apache.org%3Ehttps://lists.apache.org/thread.html/r954d80fd18e9dafef6e813963eb7e08c228151c2b6268ecd63b35d1f%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rc9e441c1576bdc4375d32526d5cf457226928e9c87b9f54ded26271c%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/rcd37d9214b08067a2e8f2b5b4fd123a1f8cb6008698d11ef44028c21%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/rdcbad6d8ce72c79827ed8c635f9a62dd919bb21c94a0b64cab2efc31%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/rddd2237b8636a48d573869006ee809262525efb2b6ffa6eff50d2a2d%40%3Cjira.kafka.apache.org%3Ehttps://lists.apache.org/thread.html/rdfd2901b8b697a3f6e2c9c6ecc688fd90d7f881937affb5144d61d6e%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/rf9abfc0223747a56694825c050cc6b66627a293a32ea926b3de22402%40%3Cissues.karaf.apache.org%3Ehttps://lists.apache.org/thread.html/rfc0db1f3c375087e69a239f9284ded72d04fbb55849eadde58fa9dc2%40%3Cissues.karaf.apache.org%3Ehttps://www.bouncycastle.org/releasenotes.htmlhttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.synopsys.com/blogs/software-security/cve-2020-28052-bouncy-castle/
2020-12-18
Published