CVE-2024-34447
published 2024-05-03CVE-2024-34447: An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.77%
51.5th percentile
An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bouncycastle | < bouncycastle 1.80-1 (forky) | bouncycastle 1.80-1 (forky) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bouncy Castle vulnerabilities
vendor_ubuntu·2026-03-18·CVSS 5.3
CVE-2025-8916 [MEDIUM] Bouncy Castle vulnerabilities
Title: Bouncy Castle vulnerabilities
Summary: Several security issues were fixed in Bouncy Castle.
It was discovered that Bouncy Castle did not sanitize user input when
inserting it into an LDAP search filter. An attacker could possibly use
this issue to perform an LDAP injection attack. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2023-33201)
It was discovered that Bouncy Castle incorrectly handled specially crafted
F2m parameters in the ECCurve algorithm. An attacker could possibly use
this issue to cause Bouncy Castle to use excessive resources, leading to a
denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-29857)
It was discovered that Bouncy
Red Hat
org.bouncycastle: Use of Incorrectly-Resolved Name or Reference
vendor_redhat·2024-05-03·CVSS 7.5
CVE-2024-34447 [HIGH] CWE-706 org.bouncycastle: Use of Incorrectly-Resolved Name or Reference
org.bouncycastle: Use of Incorrectly-Resolved Name or Reference
An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.
A flaw was found in Bouncy Castle Java Cryptography APIs. Affected versions of this package are vulnerable to a use of incorrectly-resolved name or reference issue when resolving domain names over an SSL socket that was created without an explicit hostname, such as i
Debian
CVE-2024-34447: bouncycastle - An issue was discovered in the Bouncy Castle Crypto Package For Java before BC T...
vendor_debian·2024·CVSS 7.5
CVE-2024-34447 [HIGH] CVE-2024-34447: bouncycastle - An issue was discovered in the Bouncy Castle Crypto Package For Java before BC T...
An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.80-1)
sid: resolved (fixed in 1.80-1)
trixie: resolved (fixed in 1.80-1)
OSV
bouncycastle vulnerabilities
osv·2026-03-18·CVSS 5.3
CVE-2023-33201 [MEDIUM] bouncycastle vulnerabilities
bouncycastle vulnerabilities
It was discovered that Bouncy Castle did not sanitize user input when
inserting it into an LDAP search filter. An attacker could possibly use
this issue to perform an LDAP injection attack. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2023-33201)
It was discovered that Bouncy Castle incorrectly handled specially crafted
F2m parameters in the ECCurve algorithm. An attacker could possibly use
this issue to cause Bouncy Castle to use excessive resources, leading to a
denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-29857)
It was discovered that Bouncy Castle leaked timing information when
handling exceptions during an RSA
OSV
Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
osv·2024-05-03
CVE-2024-34447 [MEDIUM] Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.
GHSA
Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
ghsa·2024-05-03
CVE-2024-34447 [MEDIUM] CWE-297 Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.
OSV
CVE-2024-34447: An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1
osv·2024-05-03·CVSS 7.5
CVE-2024-34447 [HIGH] CVE-2024-34447: An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1
An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.
No detection rules found.
No public exploits indexed.
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9034447https://security.netapp.com/advisory/ntap-20240614-0007/https://www.bouncycastle.org/latest_releases.htmlhttps://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9034447https://security.netapp.com/advisory/ntap-20240614-0007/https://www.bouncycastle.org/latest_releases.html
2024-05-03
Published