CVE-2024-30171: Bouncycastle Bouncy Castle For Java

Medium severity, CVSS 5.9. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.

Affected products

  • Bouncycastle Bouncy Castle For Java: before 1.78 (fixed in 1.78)
  • Netapp Active Iq Unified Manager: any version
  • Netapp Bluexp: any version
  • Netapp Oncommand Workflow Automation: any version
  • Netapp Ontap Tools: version 9 only

Published 2024-05-14. Last modified 2026-06-17.