Fixed
Details
Details
Assignee
Christian Pape
Christian PapeReporter
Shobha Ramachandrappa
Shobha RamachandrappaHB Grooming Date
Mar 19, 2024
HB Backlog Status
Refined Backlog
Sprint
None
Fix versions
Affects versions
Priority
PagerDuty
PagerDuty
Created March 19, 2024 at 11:12 AM
Updated July 8, 2024 at 4:41 PM
Resolved June 18, 2024 at 11:00 AM
Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when an attacker is able to observe timing information for the generation of multiple deterministic ECDSA signatures.