CVE-2024-30171
MediumVulnerability Description
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
USN-8108-1
USN-8108-1: Bouncy Castle vulnerabilities
CPUJAN2026
Oracle Critical Patch Update Advisory - January 2026
CPUJAN2025
Oracle Critical Patch Update Advisory - January 2025
References & Resources
-
https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9030171cve@mitre.org
-
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9030171cve@mitre.org
-
https://security.netapp.com/advisory/ntap-20240614-0008/cve@mitre.org
-
https://www.bouncycastle.org/latest_releases.htmlcve@mitre.org
-
https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9030171af854a3a-2127-422b-91ae-364da2661108
-
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9030171af854a3a-2127-422b-91ae-364da2661108
-
https://security.netapp.com/advisory/ntap-20240614-0008/af854a3a-2127-422b-91ae-364da2661108
-
https://www.bouncycastle.org/latest_releases.htmlaf854a3a-2127-422b-91ae-364da2661108
Severity Details
Weakness Type (CWE)
Observable Discrepancy
- Description
- The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or…
- Typical Severity
- Medium
- Abstraction Level
- Base
Key Information
- Published Date
- May 14, 2024
