Uploaded image for project: 'Karaf'
  1. Karaf
  2. KARAF-7240

Upgrade bcprov 1.68 artifacts to mitigate CVE-2020-28052

    XMLWordPrintableJSON

Details

    • Dependency upgrade
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 4.3.2
    • 4.2.12, 4.3.3
    • karaf
    • None
    • Apache Karaf - OSGi

    Description

      We are using Apache Karaf 4.3.2 in our project and our security scans report CVE-2020-28052 (https://nvd.nist.gov/vuln/detail/CVE-2020-28052) on our package because Karaf by default packs bcprov and bcpkix 1.66 versions. The fix for the specified CVE is to use bcprov and bcpkis 1.67 and higher. Apache Karaf should update to use later versions of these bouncy castle 3pps so that this CVE is mitigated.

      Attachments

        Activity

          People

            jbonofre Jean-Baptiste Onofré
            karthickm512 Karthick
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: