You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Affected versions of this package are vulnerable to Infinite loop in ED25519 verification in the ScalarUtil class. An attacker can send a malicious signature and public key to trigger denial of service.
Remediation
Upgrade org.bouncycastle:bcprov-jdk18on to version 1.78 or higher.
CVE-2024-30172 - Infinite loop in org.bouncycastle:bcprov-jdk18on
org.bouncycastle:bcprov-jdk18on
Introduced through: org.keycloak:[email protected] › org.keycloak:[email protected] › org.keycloak:[email protected] › org.bouncycastle:[email protected]
Overview
Affected versions of this package are vulnerable to Infinite loop in ED25519 verification in the
ScalarUtil
class. An attacker can send a malicious signature and public key to trigger denial of service.Remediation
Upgrade
org.bouncycastle:bcprov-jdk18on
to version 1.78 or higher.References
The text was updated successfully, but these errors were encountered: