Skip to content

Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")

Moderate severity GitHub Reviewed Published May 14, 2024 to the GitHub Advisory Database • Updated Jun 14, 2024

Package

nuget BouncyCastle (NuGet)

Affected versions

< 2.3.1

Patched versions

None
nuget BouncyCastle.Cryptography (NuGet)
< 2.3.1
2.3.1
maven org.bouncycastle:bcpkix-jdk14 (Maven)
< 1.78
1.78
maven org.bouncycastle:bcpkix-jdk15to18 (Maven)
< 1.78
1.78
maven org.bouncycastle:bcpkix-jdk18on (Maven)
< 1.78
1.78
maven org.bouncycastle:bcprov-jdk14 (Maven)
< 1.78
1.78
maven org.bouncycastle:bcprov-jdk15on (Maven)
< 1.78
1.78
maven org.bouncycastle:bcprov-jdk15to18 (Maven)
< 1.78
1.78
maven org.bouncycastle:bcprov-jdk18on (Maven)
< 1.78
1.78
maven org.bouncycastle:bctls-fips (Maven)
< 1.0.19
1.0.19
maven org.bouncycastle:bctls-jdk14 (Maven)
< 1.78
1.78
maven org.bouncycastle:bctls-jdk15to18 (Maven)
< 1.78
1.78
maven org.bouncycastle:bctls-jdk18on (Maven)
< 1.78
1.78
Published by the National Vulnerability Database May 14, 2024
Published to the GitHub Advisory Database May 14, 2024
Reviewed May 14, 2024
Last updated Jun 14, 2024

Severity

Moderate
5.9
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CVE ID

CVE-2024-30171

GHSA ID

GHSA-v435-xc8x-wvr9

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.