CVE Vulnerabilities

CVE-2024-34447

Published: May 03, 2024 | Modified: Jun 14, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM

An issue was discovered in Bouncy Castle Java Cryptography APIs before BC 1.78. When endpoint identification is enabled in the BCJSSE and an SSL socket is created without an explicit hostname (as happens with HttpsURLConnection), hostname verification could be performed against a DNS-resolved IP address in some situations, opening up a possibility of DNS poisoning.

Affected Software

Name Vendor Start Version End Version
Red Hat AMQ Broker 7 RedHat org.bouncycastle:bcprov-jdk18on *
Red Hat build of Quarkus 3.8.5.redhat RedHat org.bouncycastle/bcprov-jdk18on:1.78.1.redhat-00002 *
Bouncycastle Ubuntu mantic *

References