CVE-2023-33201
published 2023-07-05CVE-2023-33201: Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.77%
51.6th percentile
Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bouncycastle | bc-java | < 1.74 | 1.74 |
| debian | bouncycastle | < bouncycastle 1.77-1 (forky) | bouncycastle 1.77-1 (forky) |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bouncy Castle vulnerabilities
vendor_ubuntu·2026-03-18·CVSS 5.3
CVE-2025-8916 [MEDIUM] Bouncy Castle vulnerabilities
Title: Bouncy Castle vulnerabilities
Summary: Several security issues were fixed in Bouncy Castle.
It was discovered that Bouncy Castle did not sanitize user input when
inserting it into an LDAP search filter. An attacker could possibly use
this issue to perform an LDAP injection attack. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2023-33201)
It was discovered that Bouncy Castle incorrectly handled specially crafted
F2m parameters in the ECCurve algorithm. An attacker could possibly use
this issue to cause Bouncy Castle to use excessive resources, leading to a
denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-29857)
It was discovered that Bouncy
Oracle
Oracle Oracle Commerce Risk Matrix: Workbench (Bouncy Castle Java Library) — CVE-2023-33201
vendor_oracle·2025-01-15·CVSS 5.3
CVE-2023-33201 [MEDIUM] Oracle Oracle Commerce Risk Matrix: Workbench (Bouncy Castle Java Library) — CVE-2023-33201
Oracle Oracle Commerce Risk Matrix: Workbench (Bouncy Castle Java Library) vulnerability
CVE: CVE-2023-33201
CVSS: 5.3
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Oracle
Oracle Oracle Systems Risk Matrix: Tools (Bouncy Castle Java Library) — CVE-2023-33201
vendor_oracle·2024-10-15·CVSS 5.3
CVE-2023-33201 [MEDIUM] Oracle Oracle Systems Risk Matrix: Tools (Bouncy Castle Java Library) — CVE-2023-33201
Oracle Oracle Systems Risk Matrix: Tools (Bouncy Castle Java Library) vulnerability
CVE: CVE-2023-33201
CVSS: 5.3
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Security (Bouncy Castle Java Library) — CVE-2023-33201
vendor_oracle·2024-07-15·CVSS 5.3
CVE-2023-33201 [MEDIUM] Oracle Oracle Communications Risk Matrix: Security (Bouncy Castle Java Library) — CVE-2023-33201
Oracle Oracle Communications Risk Matrix: Security (Bouncy Castle Java Library) vulnerability
CVE: CVE-2023-33201
CVSS: 5.3
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (Bouncy Castle Java Library) — CVE-2023-33201
vendor_oracle·2024-04-15·CVSS 5.3
CVE-2023-33201 [MEDIUM] Oracle Oracle Communications Risk Matrix: Configuration (Bouncy Castle Java Library) — CVE-2023-33201
Oracle Oracle Communications Risk Matrix: Configuration (Bouncy Castle Java Library) vulnerability
CVE: CVE-2023-33201
CVSS: 5.3
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (Bouncy Castle Java Library) — CVE-2023-33201
vendor_oracle·2024-01-15·CVSS 5.3
CVE-2023-33201 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Security (Bouncy Castle Java Library) — CVE-2023-33201
Oracle Oracle Communications Applications Risk Matrix: Security (Bouncy Castle Java Library) vulnerability
CVE: CVE-2023-33201
CVSS: 5.3
Protocol: LDAP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Communications Risk Matrix: General (Bouncy Castle Java Library) — CVE-2023-33201
vendor_oracle·2023-10-15·CVSS 5.3
CVE-2023-33201 [MEDIUM] Oracle Oracle Communications Risk Matrix: General (Bouncy Castle Java Library) — CVE-2023-33201
Oracle Oracle Communications Risk Matrix: General (Bouncy Castle Java Library) vulnerability
CVE: CVE-2023-33201
CVSS: 5.3
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Red Hat
bouncycastle: potential blind LDAP injection attack using a self-signed certificate
vendor_redhat·2023-06-16·CVSS 5.3
CVE-2023-33201 [MEDIUM] CWE-200 bouncycastle: potential blind LDAP injection attack using a self-signed certificate
bouncycastle: potential blind LDAP injection attack using a self-signed certificate
Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.
A flaw was found in Bouncy Castle 1.73. This issue targets the fix of LDAP wild cards. Before the fix there was no validation for the X.500 name of any certificate, subject, or issuer, so the presence of a wild card may lead to information disclosure. This could allow a malicious user to obtain unauthorized informa
Debian
CVE-2023-33201: bouncycastle - Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerabilit...
vendor_debian·2023·CVSS 5.3
CVE-2023-33201 [MEDIUM] CVE-2023-33201: bouncycastle - Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerabilit...
Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.77-1)
sid: resolved (fixed in 1.77-1)
trixie: resolved (fixed in 1.77-1)
OSV
bouncycastle vulnerabilities
osv·2026-03-18·CVSS 5.3
CVE-2023-33201 [MEDIUM] bouncycastle vulnerabilities
bouncycastle vulnerabilities
It was discovered that Bouncy Castle did not sanitize user input when
inserting it into an LDAP search filter. An attacker could possibly use
this issue to perform an LDAP injection attack. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2023-33201)
It was discovered that Bouncy Castle incorrectly handled specially crafted
F2m parameters in the ECCurve algorithm. An attacker could possibly use
this issue to cause Bouncy Castle to use excessive resources, leading to a
denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-29857)
It was discovered that Bouncy Castle leaked timing information when
handling exceptions during an RSA
GHSA
Bouncy Castle For Java LDAP injection vulnerability
ghsa·2023-07-05
CVE-2023-33201 [MEDIUM] CWE-295 Bouncy Castle For Java LDAP injection vulnerability
Bouncy Castle For Java LDAP injection vulnerability
Bouncy Castle provides the `X509LDAPCertStoreSpi.java` class which can be used in conjunction with the CertPath API for validating certificate paths. Pre-1.73 the implementation did not check the X.500 name of any certificate, subject, or issuer being passed in for LDAP wild cards, meaning the presence of a wild car may lead to Information Disclosure.
A potential attack would be to generate a self-signed certificate with a subject name that contains special characters, e.g: `CN=Subject*)(objectclass=`. This will be included into the filter and provides the attacker ability to specify additional attributes in the search query. This can be exploited as a blind LDAP injection: an attacker can enumerate valid attribute values using the bool
OSV
CVE-2023-33201: Bouncy Castle For Java before 1
osv·2023-07-05·CVSS 5.3
CVE-2023-33201 [MEDIUM] CVE-2023-33201: Bouncy Castle For Java before 1
Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.
OSV
Bouncy Castle For Java LDAP injection vulnerability
osv·2023-07-05
CVE-2023-33201 [MEDIUM] Bouncy Castle For Java LDAP injection vulnerability
Bouncy Castle For Java LDAP injection vulnerability
Bouncy Castle provides the `X509LDAPCertStoreSpi.java` class which can be used in conjunction with the CertPath API for validating certificate paths. Pre-1.73 the implementation did not check the X.500 name of any certificate, subject, or issuer being passed in for LDAP wild cards, meaning the presence of a wild car may lead to Information Disclosure.
A potential attack would be to generate a self-signed certificate with a subject name that contains special characters, e.g: `CN=Subject*)(objectclass=`. This will be included into the filter and provides the attacker ability to specify additional attributes in the search query. This can be exploited as a blind LDAP injection: an attacker can enumerate valid attribute values using the bool
No detection rules found.
No public exploits indexed.
Huntress
CVE-2023-33201 Vulnerability: Analysis, Detection, Removal | Huntress
blogs_huntress·CVSS 5.3
CVE-2023-33201 [MEDIUM] CVE-2023-33201 Vulnerability: Analysis, Detection, Removal | Huntress
## CVE-2023-33201 Vulnerability
Published: 12/05/2025
Written by: Lizzie Danielson
## What is CVE-2023-33201 Vulnerability?
CVE-2023-33201 is a remote code execution vulnerability within the org.bouncycastle.bcprov-ext-jdk15to18 Maven package. It was assigned after researchers identified a flaw in how the library processes specially crafted inputs, allowing malicious actors to execute arbitrary code. Its severe nature stems from its ability to bypass authentication and exploit cryptographic operations that are otherwise trusted in applications. The Common Vulnerabilities and Exposures (CVE) identifier for this issue is CVE-2023-33201.
## When was it discovered?
The vulnerability was publicly disclosed on May 23, 2023, by the cybersecurity community following a detailed report from se
arXiv
CleanVul: Automatic Function-Level Vulnerability Detection in Code Commits Using LLM Heuristics
arxiv_fulltext·2025-09-11
CleanVul: Automatic Function-Level Vulnerability Detection in Code Commits Using LLM Heuristics
: Toward High-Quality Function-Level Vulnerability Datasets via LLM-Based Noise Reduction
Yikun Li
[email protected]
https://orcid.org/0000-0002-1566-725X
Singapore Management University
Singapore
Singapore
Ting Zhang
Singapore Management University
Singapore
Singapore
Ratnadira Widyasari
Singapore Management University
Singapore
Singapore
Yan Naing Tun
Singapore Management University
Singapore
Singapore
Huu Hung Nguyen
Singapore Management University
Singapore
Singapore
Tan Bui
Singapore Management University
Singapore
Singapore
Ivana Clairine Irsan
Singapore Management University
Singapore
Singapore
Yiran Cheng
Singapore Management University
Singapore
Singapore
Xiang Lan
North Carolina State University
Raleigh, North Carolina
United States
Han Wei Ang
GovTech
Singap
https://bouncycastle.orghttps://github.com/bcgit/bc-java/commit/e8c409a8389c815ea3fda5e8b94c92fdfe583bcchttps://github.com/bcgit/bc-java/wiki/CVE-2023-33201https://lists.debian.org/debian-lts-announce/2023/08/msg00000.htmlhttps://security.netapp.com/advisory/ntap-20230824-0008/https://bouncycastle.orghttps://github.com/bcgit/bc-java/commit/e8c409a8389c815ea3fda5e8b94c92fdfe583bcchttps://github.com/bcgit/bc-java/wiki/CVE-2023-33201https://lists.debian.org/debian-lts-announce/2023/08/msg00000.htmlhttps://security.netapp.com/advisory/ntap-20230824-0008/
2023-07-05
Published