Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
BouncyCastle JCE TLS Bleichenbacher/ROBOT
Vulnerability Description
BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable application. This vulnerability is referred to as "ROBOT."
CVSS Information
N/A
Vulnerability Type
通过差异性导致的信息暴露
Vulnerability Title
Legion of the Bouncy Castle TLS 加密问题漏洞
Vulnerability Description
Legion of the Bouncy Castle是澳大利亚Legion of the Bouncy Castle公司的一个用于Java平台的开源的轻量级密码包。TLS是其中的一个安全传输层协议。 Legion of the Bouncy Castle TLS 1.0.3之前的版本中存在安全漏洞,该漏洞源于程序对加密函数使用了JCE(Java加密扩展)。攻击者可利用该漏洞从受影响的应用程序中找回密钥。
CVSS Information
N/A
Vulnerability Type
N/A