13
Views
0
Comments
[JWT] High Vulnerability found in BouncyCastle.Crypto - CVE-2024-30172
jwt
Service icon
Forge asset by João Almeida
Application Type
Service

Hi there

We're getting a report of a vulnerability in this module for BouncyCastle.Crypto 1.8.9. It's a high vulnerability has a CVSSv3 score of 7.5 

Details are as follows:
An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key. 

Can this please be updated in the next release? 

Kind regards

Daniel


Community GuidelinesBe kind and respectful, give credit to the original source of content, and search for duplicates before posting.