CVE-2018-1000180
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
- Affected products
- Bouncy Castle, Bouncy Castle Bc-Fja, Oracle Weblogic Server, Suse
- Bouncycastle Bc-java
- ≤ 1.59
- Bouncycastle Fips Java Api
- ≤ 1.0.1
- Fix
- Available
- CVSS 3.0
- 7.5 HIGH
- EPSS
- 3.6% (88th percentile)
- Weakness
- CWE-327
- NVD status
- Modified
- Published
- 2018-06-05
CVE-2018-1000180 at NVD
No indexed exploits for CVE-2018-1000180 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-1000180 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.