Today > | 5 Medium | 2 Low vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-30171

May 14, 2024, 4:13 p.m.

Product(s) Impacted

Bouncy Castle Java TLS API

  • before 1.78

JSSE Provider

  • before 1.78

Description

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.

Weaknesses

Date

Published: May 14, 2024, 3:21 p.m.

Last Modified: May 14, 2024, 4:13 p.m.

Status : Awaiting Analysis

CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

More info

Source

cve@mitre.org

References