Logic error in Legion of the Bouncy Castle BC Java
High severity
GitHub Reviewed
Published
Apr 30, 2021
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
>= 1.65, < 1.67
Patched versions
1.67
Description
Published by the National Vulnerability Database
Dec 18, 2020
Reviewed
Mar 19, 2021
Published to the GitHub Advisory Database
Apr 30, 2021
Last updated
Jan 27, 2023
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
References