An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cryostat 3 on RHEL 8 | RedHat | cryostat-tech-preview/cryostat-db-rhel8:3.0.0-3 | * |
Cryostat 3 on RHEL 8 | RedHat | cryostat-tech-preview/cryostat-grafana-dashboard-rhel8:3.0.0-2 | * |
Cryostat 3 on RHEL 8 | RedHat | cryostat-tech-preview/cryostat-operator-bundle:3.0.0-2 | * |
Cryostat 3 on RHEL 8 | RedHat | cryostat-tech-preview/cryostat-ose-oauth-proxy-rhel8:3.0.0-3 | * |
Cryostat 3 on RHEL 8 | RedHat | cryostat-tech-preview/cryostat-reports-rhel8:3.0.0-2 | * |
Cryostat 3 on RHEL 8 | RedHat | cryostat-tech-preview/cryostat-rhel8:3.0.0-2 | * |
Cryostat 3 on RHEL 8 | RedHat | cryostat-tech-preview/cryostat-rhel8-operator:3.0.0-2 | * |
Cryostat 3 on RHEL 8 | RedHat | cryostat-tech-preview/cryostat-storage-rhel8:3.0.0-3 | * |
Cryostat 3 on RHEL 8 | RedHat | cryostat-tech-preview/jfr-datasource-rhel8:3.0.0-2 | * |
Red Hat AMQ Broker 7 | RedHat | org.bouncycastle-bcprov-jdk18on | * |
Red Hat build of Apache Camel 4.4.1 for Spring Boot | RedHat | org.bouncycastle-bcprov-jdk18on | * |
Red Hat Build of Apache Camel 4.4 for Quarkus 3.8 | RedHat | org.bouncycastle-bcprov-jdk18on | * |
Red Hat build of Quarkus 3.8.5.redhat | RedHat | org.bouncycastle/bcprov-jdk18on:1.78.1.redhat-00002 | * |
Red Hat JBoss Enterprise Application Platform 7 | RedHat | org.bouncycastle-bcprov-jdk18on | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 | RedHat | eap7-bouncycastle-0:1.78.1-1.redhat_00002.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 | RedHat | eap7-bouncycastle-0:1.78.1-1.redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 | RedHat | eap7-bouncycastle-0:1.78.1-1.redhat_00002.1.el7eap | * |
Red Hat JBoss Enterprise Application Platform 8 | RedHat | org.bouncycastle-bcprov-jdk18on | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-bouncycastle-0:1.78.1-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-activemq-artemis-0:2.21.0-5.redhat_00052.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-angus-0:2.0.3-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-angus-activation-0:2.0.1-3.redhat_00006.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-apache-commons-beanutils-0:1.9.4-13.redhat_00004.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-apache-commons-cli-0:1.4.0-2.redhat_00003.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-apache-commons-codec-0:1.15.0-6.redhat_00016.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-apache-cxf-0:4.0.4-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-apache-cxf-xjc-utils-0:4.0.0-5.redhat_00003.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-apache-mime4j-0:0.8.11-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-apache-sshd-0:2.12.1-2.redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-bouncycastle-0:1.78.1-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-byte-buddy-0:1.14.18-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-caffeine-0:3.1.8-2.redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-eap-product-conf-parent-0:800.3.0-2.GA_redhat_00004.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-guava-failureaccess-0:1.0.2-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-guava-libraries-0:33.0.0-1.jre_redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-hal-console-0:3.6.19-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-hornetq-0:2.4.9-4.Final_redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-httpcomponents-asyncclient-0:4.1.5-3.redhat_00005.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-httpcomponents-client-0:4.5.14-4.redhat_00012.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-httpcomponents-core-0:4.4.16-4.redhat_00010.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-infinispan-0:14.0.30-2.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jakarta-json-api-0:2.1.3-1.redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jakarta-mail-0:2.1.3-1.redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jakarta-servlet-api-0:6.0.0-5.redhat_00006.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jakarta-websocket-0:2.1.1-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jakarta-xml-bind-api-0:4.0.1-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jandex-0:3.0.8-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jasypt-0:1.9.3-4.redhat_00004.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-java-classmate-0:1.5.1-3.redhat_00004.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jaxb-0:4.0.5-2.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jboss-metadata-0:16.0.0-3.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jboss-openjdk-orb-0:10.1.0-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jbossws-cxf-0:7.1.0-1.Final_redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-joda-time-0:2.12.7-1.redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jsf-impl-0:4.0.7-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-mod_cluster-0:2.0.3-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-neethi-0:3.2.0-1.redhat_00004.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-netty-0:4.1.108-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-netty-transport-native-epoll-0:4.1.108-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-netty-xnio-transport-0:0.1.10-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-opensaml-0:4.2.0-4.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-parsson-0:1.1.5-2.redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-reactivex-rxjava-0:3.1.8-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-resteasy-0:6.2.7-2.Final_redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-slf4j-0:2.0.13-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-stax2-api-0:4.2.2-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-velocity-0:2.3.0-3.redhat_00009.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-weld-core-0:5.1.2-2.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-wildfly-0:8.0.3-9.GA_redhat_00004.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-wildfly-discovery-0:1.3.0-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-wildfly-elytron-0:2.2.6-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-wsdl4j-0:1.6.3-5.redhat_00008.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-wss4j-0:3.0.3-1.redhat_00008.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-xml-security-0:3.0.4-1.redhat_00005.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-yasson-0:3.0.3-3.redhat_00002.1.el9eap | * |
Bouncycastle | Ubuntu | mantic | * |