{"id":"CVE-2020-28052","details":"An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.","aliases":["GHSA-73xv-w5gp-frxh"],"modified":"2026-05-18T05:53:27.010016376Z","published":"2020-12-18T01:15:12.587Z","related":["openSUSE-SU-2024:10661-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"last_affected":"14.2.0"},{"last_affected":"14.3.0"},{"last_affected":"14.5.0"}],"cpes":["cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5.0:*:*:*:*:*:*:*"],"vendor_product":"oracle:banking_corporate_lending_process_management","source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"14.2.0"},{"last_affected":"14.3.0"},{"last_affected":"14.5.0"}],"cpes":["cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.5.0:*:*:*:*:*:*:*"],"vendor_product":"oracle:banking_credit_facilities_process_management","source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"14.2.0"},{"last_affected":"14.3.0"},{"last_affected":"14.5.0"}],"cpes":["cpe:2.3:a:oracle:banking_extensibility_workbench:14.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_extensibility_workbench:14.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_extensibility_workbench:14.5.0:*:*:*:*:*:*:*"],"vendor_product":"oracle:banking_extensibility_workbench","source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"14.2.0"},{"last_affected":"14.3.0"},{"last_affected":"14.5.0"}],"cpes":["cpe:2.3:a:oracle:banking_supply_chain_finance:14.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_supply_chain_finance:14.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_supply_chain_finance:14.5.0:*:*:*:*:*:*:*"],"vendor_product":"oracle:banking_supply_chain_finance","source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"14.2.0"},{"last_affected":"14.3.0"},{"last_affected":"14.5.0"}],"cpes":["cpe:2.3:a:oracle:banking_virtual_account_management:14.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_virtual_account_management:14.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:banking_virtual_account_management:14.5.0:*:*:*:*:*:*:*"],"vendor_product":"oracle:banking_virtual_account_management","source":"CPE_FIELD"},{"extracted_events":[{"fixed":"21.1.2"}],"cpes":["cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:*"],"vendor_product":"oracle:blockchain_platform","source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"11.3.2"}],"vendor_product":"oracle:commerce_guided_search","cpes":["cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:*"],"source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"3.9m0p3"}],"vendor_product":"oracle:communications_application_session_controller","cpes":["cpe:2.3:a:oracle:communications_application_session_controller:3.9m0p3:*:*:*:*:*:*:*"],"source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"1.2.1"}],"vendor_product":"oracle:communications_cloud_native_core_network_slice_selection_function","cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.2.1:*:*:*:*:*:*:*"],"source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"3.0.2.2.0"}],"cpes":["cpe:2.3:a:oracle:communications_convergence:3.0.2.2.0:*:*:*:*:*:*:*"],"vendor_product":"oracle:communications_convergence","source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"8.0.2"},{"last_affected":"8.1"}],"vendor_product":"oracle:communications_messaging_server","cpes":["cpe:2.3:o:oracle:communications_messaging_server:8.0.2:*:*:*:*:*:*:*","cpe:2.3:o:oracle:communications_messaging_server:8.1:*:*:*:*:*:*:*"],"source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"12.0.0.3.0"}],"cpes":["cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.3.0:*:*:*:*:*:*:*"],"vendor_product":"oracle:communications_pricing_design_center","source":"CPE_FIELD"},{"extracted_events":[{"introduced":"8.0.0"},{"last_affected":"8.2.4.0"}],"cpes":["cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:*"],"vendor_product":"oracle:communications_session_report_manager","source":"CPE_FIELD"},{"extracted_events":[{"introduced":"8.2.0"},{"last_affected":"8.2.4"}],"vendor_product":"oracle:communications_session_route_manager","cpes":["cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:*"],"source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"9.2.5.3"}],"cpes":["cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*"],"vendor_product":"oracle:jd_edwards_enterpriseone_tools","source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"8.56"},{"last_affected":"8.57"},{"last_affected":"8.58"}],"cpes":["cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*","cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*","cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*"],"vendor_product":"oracle:peoplesoft_enterprise_peopletools","source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"4.3.0.6.0"},{"last_affected":"4.4.0.0.0"},{"last_affected":"4.4.0.2.0"},{"last_affected":"4.4.0.3.0"}],"cpes":["cpe:2.3:a:oracle:utilities_framework:4.3.0.6.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:utilities_framework:4.4.0.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:utilities_framework:4.4.0.2.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:utilities_framework:4.4.0.3.0:*:*:*:*:*:*:*"],"vendor_product":"oracle:utilities_framework","source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"11.1.1.9.0"},{"last_affected":"12.2.1.3.0"},{"last_affected":"12.2.1.4.0"}],"cpes":["cpe:2.3:a:oracle:webcenter_portal:11.1.1.9.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*"],"vendor_product":"oracle:webcenter_portal","source":"CPE_FIELD"}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r167dbc42ef7c59802c2ca1ac14735ef9cf687c25208229993d6206fe%40%3Cissues.karaf.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r175f5a25d100dbe2b1bd3459b3ce882a84c3ff91b120ed4ff2d57b53%40%3Ccommits.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r25d53acd06f29244b8a103781b0339c5e7efee9099a4d52f0c230e4a%40%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r2ddabd06d94b60cfb0141e4abb23201c628ab925e30742f61a04d013%40%3Cissues.karaf.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r30a139c165b3da6e0d5536434ab1550534011b1fdfcd2f5d95892c5b%40%3Cissues.karaf.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r37d332c0bf772f4982d1fdeeb2f88dd71dab6451213e69e43734eadc%40%3Ccommits.pulsar.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r4e1619cfefcd031fac62064a3858f5c9229eef907bd5d8ef14c594fc%40%3Cissues.karaf.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r77af3ac7c3bfbd5454546e13faf7aec21d627bdcf36c9ca240436b94%40%3Cissues.karaf.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r8c36ba34e80e05eecb1f80071cc834d705616f315b634ec0c7d8f42e%40%3Cissues.solr.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r954d80fd18e9dafef6e813963eb7e08c228151c2b6268ecd63b35d1f%40%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rc9e441c1576bdc4375d32526d5cf457226928e9c87b9f54ded26271c%40%3Cissues.karaf.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rcd37d9214b08067a2e8f2b5b4fd123a1f8cb6008698d11ef44028c21%40%3Cissues.karaf.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rdcbad6d8ce72c79827ed8c635f9a62dd919bb21c94a0b64cab2efc31%40%3Cissues.karaf.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rddd2237b8636a48d573869006ee809262525efb2b6ffa6eff50d2a2d%40%3Cjira.kafka.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rdfd2901b8b697a3f6e2c9c6ecc688fd90d7f881937affb5144d61d6e%40%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rf9abfc0223747a56694825c050cc6b66627a293a32ea926b3de22402%40%3Cissues.karaf.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rfc0db1f3c375087e69a239f9284ded72d04fbb55849eadde58fa9dc2%40%3Cissues.karaf.apache.org%3E"},{"type":"ADVISORY","url":"https://www.bouncycastle.org/releasenotes.html"},{"type":"FIX","url":"https://github.com/bcgit/bc-java/wiki/CVE-2020-28052"},{"type":"FIX","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"EVIDENCE","url":"https://www.synopsys.com/blogs/software-security/cve-2020-28052-bouncy-castle/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/karaf","events":[{"introduced":"0"},{"last_affected":"aeb61114a0ce221ed977828f56469107f7167ba5"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"4.3.2"}],"cpe":"cpe:2.3:a:apache:karaf:4.3.2:*:*:*:*:*:*:*","source":"CPE_FIELD"}}],"versions":["karaf-4.3.2","karaf-4.3.1","karaf-4.3.0","karaf-4.3.0.RC1","karaf-4.2.3","karaf-4.2.2","karaf-4.2.1","karaf-4.2.0","karaf-4.2.0.M2","karaf-4.2.0.M1","karaf-4.1.1","karaf-4.1.0","karaf-4.0.4","karaf-4.0.3","karaf-4.0.2","karaf-4.0.1","karaf-4.0.0.M2","karaf-4.0.0.M1","karaf-3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-28052.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/bcgit/bc-java","events":[{"introduced":"0"},{"last_affected":"3b40be3ca8f72c84cc4092aadde3a1edea2cf726"},{"last_affected":"ed1c8899b1b5ce0ff26feda81708c21b011f9750"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.65"},{"last_affected":"1.66"}],"cpe":["cpe:2.3:a:bouncycastle:bc-java:1.65:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bc-java:1.66:*:*:*:*:*:*:*"],"source":"CPE_FIELD"}}],"versions":["r1rv66","r1rv65","r1rv64","r1rv63","r1rv62","r1rv61","r1v60","r1rv60","r1rv59","r1rv58","r1rv57","r1rv56","r1rv55","r1rv54","r1rv53","r1rv52","r1rv51","r1rv50","r1rv49"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-28052.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}