CVE Vulnerabilities

CVE-2023-33201

Improper Certificate Validation

Published: Jul 05, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificates Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Bc-javaBouncycastle*1.74 (excluding)
AMQ Broker 7.11.5RedHatbouncycastle*
Cryostat 2 on RHEL 8RedHatcryostat-tech-preview/cryostat-grafana-dashboard-rhel8:2.4.0-2*
Cryostat 2 on RHEL 8RedHatcryostat-tech-preview/cryostat-operator-bundle:2.4.0-2*
Cryostat 2 on RHEL 8RedHatcryostat-tech-preview/cryostat-reports-rhel8:2.4.0-2*
Cryostat 2 on RHEL 8RedHatcryostat-tech-preview/cryostat-rhel8:2.4.0-2*
Cryostat 2 on RHEL 8RedHatcryostat-tech-preview/cryostat-rhel8-operator:2.4.0-3*
Cryostat 2 on RHEL 8RedHatcryostat-tech-preview/jfr-datasource-rhel8:2.4.0-2*
Red Hat AMQ Streams 2.5.0RedHat*
Red Hat AMQ Streams 2.6.0RedHatbouncycastle*
Red Hat AMQ Streams 2.7.0RedHat*
Red Hat Fuse 7.12RedHatbouncycastle*
Red Hat JBoss Enterprise Application Platform 7RedHatbouncycastle*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-bouncycastle-0:1.76.0-4.redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-bouncycastle-0:1.76.0-4.redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-bouncycastle-0:1.76.0-4.redhat_00001.1.el7eap*
Red Hat Single Sign-On 7RedHatbouncycastle*
Red Hat Single Sign-On 7.6 for RHEL 7RedHatrh-sso7-keycloak-0:18.0.11-2.redhat_00001.1.el7sso*
Red Hat Single Sign-On 7.6 for RHEL 8RedHatrh-sso7-keycloak-0:18.0.11-2.redhat_00001.1.el8sso*
Red Hat Single Sign-On 7.6 for RHEL 9RedHatrh-sso7-keycloak-0:18.0.11-2.redhat_00001.1.el9sso*
RHEL-8 based Middleware ContainersRedHatrh-sso-7/sso76-openshift-rhel8:7.6-36*
RHINT Camel-Springboot 3.18.3.2RedHatbouncycastle*
RHPAM 7.13.5 asyncRedHatbouncycastle*
BouncycastleUbuntubionic*
BouncycastleUbuntufocal*
BouncycastleUbuntukinetic*
BouncycastleUbuntulunar*
BouncycastleUbuntumantic*
BouncycastleUbuntuoracular*
BouncycastleUbuntuplucky*
BouncycastleUbuntutrusty*
BouncycastleUbuntuxenial*

Potential Mitigations

References