[ 
https://issues.apache.org/jira/browse/TOMEE-3808?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Richard Zowalla closed TOMEE-3808.
----------------------------------
    Resolution: Won't Fix

> TomEE plus is affected by BDSA-2018-5235 vulnerability
> ------------------------------------------------------
>
>                 Key: TOMEE-3808
>                 URL: https://issues.apache.org/jira/browse/TOMEE-3808
>             Project: TomEE
>          Issue Type: Bug
>    Affects Versions: 8.0.6, 8.0.7, 8.0.8
>            Reporter: Jayaprakash
>            Priority: Minor
>
> Bouncy Castle jar flagged by a security tool, Blackduck in our application. 
> The description is as follows, 
> {quote}Bouncy Castle contains a weak key-hash message authentication code 
> (HMAC) that is only 16 bits long which can result in hash collisions. This is 
> due to an error within the BKS version 1 keystore (BKS-V1) files and could 
> lead to an attacker being able to affect the integrity of these files.
> {quote}
> {quote}Note: This issue issue occurs due to functionality that was 
> re-introduced following the fix for CVE-2018-5382 (BDSA-2018-1190).
> {quote}
> Fix is available in from version *1.69*, a new property has been added to 
> disable BKS-V1 by defaultwith this 
> commit([https://github.com/bcgit/bc-java/commit/7b66244e14488c5c981415b02ff71837ff3d2d50).]
> The impact of this vulnerability depends on the usage of BKS-V1 keystore in 
> TomEE. Please confirm the usage?
>   



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to