CVE-2023-33201
Last modified
CVE-2023-33201 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation process, Bouncy Castle inserts the certificate's Subject Name into an LDAP search filter without any escaping, which leads to an LDAP injection vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bouncycastle | Bc-Java | < 1.74 |
References
- https://bouncycastle.orgProduct
- https://github.com/bcgit/bc-java/wiki/CVE-2023-33201Vendor Advisory
- https://bouncycastle.orgProduct
- https://github.com/bcgit/bc-java/wiki/CVE-2023-33201Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-33201?
How severe is CVE-2023-33201?
How do I fix CVE-2023-33201?
Are you affected by CVE-2023-33201?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
