GHSA-hr8g-6v94-x4m9
MODERATECVE-2023-33201Bouncy Castle provides the X509LDAPCertStoreSpi.java class which can be used in conjunction with the CertPath API for validating certificate paths. Pre-1.73 the implementation did not check the X.500 name of any certificate, subject, or issuer being passed in for LDAP wild cards, meaning the presence of a wild car may lead to Information Disclosure.
- Affected
- >= 1.49, < 1.74
- Fixed in
- 1.74
- Weakness
- CWE-295
- Published
- 2023-07-05
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereference