CVE-2024-30171: Bouncycastle Bouncy Castle For Java
Medium severity, CVSS 5.9. EPSS: 0.9% chance of exploitation in the next 30 days.
An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.
Affected products
- Bouncycastle Bouncy Castle For Java: before 1.78 (fixed in 1.78)
- Netapp Active Iq Unified Manager: any version
- Netapp Bluexp: any version
- Netapp Oncommand Workflow Automation: any version
- Netapp Ontap Tools: version 9 only
Published 2024-05-14. Last modified 2026-06-17.