CVE-2022-45146
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to be zeroed out while still in use by the module, resulting in errors or potential information loss. NOTE: FIPS compliant users are unaffected because the FIPS certification is only for Java 7, 8, and 11.
Se descubrió un problema en la API FIPS Java de Bouncy Castle BC-FJA antes de la versión 1.0.2.4. Los cambios en el recolector de basura JVM en Java 13 y versiones posteriores desencadenan un problema en los módulos BC-FJA FIPS donde es posible que las claves temporales utilizadas por el módulo se pongan a cero mientras el módulo aún las usa, lo que genera errores o información potencial. pérdida. NOTA: Los usuarios que cumplen con FIPS no se ven afectados porque la certificación FIPS es solo para Java 7, 8 y 11.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-11 CVE Reserved
- 2022-11-21 CVE Published
- 2024-02-14 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-416: Use After Free
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://mvnrepository.com/artifact/org.bouncycastle/bc-fips |
URL | Date | SRC |
---|---|---|
https://github.com/bcgit/bc-java/wiki/CVE-2022-45146 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.bouncycastle.org/latest_releases.html | 2024-02-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bouncycastle Search vendor "Bouncycastle" | Fips Java Api Search vendor "Bouncycastle" for product "Fips Java Api" | < 1.0.2.4 Search vendor "Bouncycastle" for product "Fips Java Api" and version " < 1.0.2.4" | - |
Affected
| in | Oracle Search vendor "Oracle" | Jdk Search vendor "Oracle" for product "Jdk" | >= 13.0.0 Search vendor "Oracle" for product "Jdk" and version " >= 13.0.0" | - |
Safe
|