
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability was discovered in the FIPS Java API of Bouncy Castle BC-FJA before version 1.0.2.4. The issue was identified in November 2022 and affects the Java Virtual Machine (JVM) garbage collector functionality in Java 13 and later versions (CVE Mitre, NVD).
The vulnerability stems from changes to the JVM garbage collector in Java 13 and later versions, which triggers an issue in the BC-FJA FIPS modules. The problem occurs when temporary keys used by the module can be zeroed out while still in use by the module, potentially leading to errors or information loss (NVD).
When exploited, this vulnerability can result in errors during cryptographic operations and potential information loss due to the premature zeroing of temporary keys that are still in active use by the FIPS module (NVD).
The vulnerability has been addressed in BC-FJA version 1.0.2.4. Users should upgrade to this version or later to mitigate the issue (Red Hat Portal).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."