CVE-2018-1000180: High severity bouncycastle FIPS Java API vulnerability
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
Other sources
Bouncy Castle could provide weaker than expected security, caused by an error in the Low-level interface to RSA key pair generator. The RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. An attacker could exploit this vulnerability to launch further attacks on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this security flaw?
The vulnerability ID of this security flaw is CVE-2018-1000180.
What is the severity level of vulnerability CVE-2018-1000180?
The severity level of vulnerability CVE-2018-1000180 is high with a severity value of 7.5.
What is the affected software for vulnerability CVE-2018-1000180?
The affected software for vulnerability CVE-2018-1000180 includes Bouncy Castle versions BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1, and earlier.
How can I fix vulnerability CVE-2018-1000180?
To fix vulnerability CVE-2018-1000180, update to Bouncy Castle version 1.60 or later.
Where can I find more information about vulnerability CVE-2018-1000180?
You can find more information about vulnerability CVE-2018-1000180 on the Bouncy Castle issue tracker and GitHub repositories.