An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 12 May 2025 18:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Bouncycastle bc-java | |
| CPEs | cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.66:*:*:*:*:*:*:* | cpe:2.3:a:bouncycastle:bc-java:1.65:*:*:*:*:*:*:* cpe:2.3:a:bouncycastle:bc-java:1.66:*:*:*:*:*:*:* | 
| Vendors & Products | Bouncycastle legion-of-the-bouncy-castle-java-crytography-api | Bouncycastle bc-java | 
Mon, 25 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Redhat jboss Enterprise Application Platform Eus | |
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products | Redhat jboss Enterprise Application Platform Eus | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2020-12-18T00:52:48
Updated: 2024-08-04T16:33:56.942Z
Reserved: 2020-11-02T00:00:00
Link: CVE-2020-28052
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2020-12-18T01:15:12.587
Modified: 2025-05-12T17:37:16.527
Link: CVE-2020-28052
 Redhat
                        Redhat