
CVE vulnerabilities reported in BouncyCastle jars

jchirantan opened this issue · 1 comments

Hi @jouniaro

CVE-2024-30171 - Medium Severity Vulnerability reported on the bouncycastle jars:

  • bcpkix-jdk15to18

Dependent libraries:

  • bcprov-jdk15to18
  • bcutil-jdk15to18

Is there any plan to upgrade the dependency?

Thanks for the note. I guess it would be good to update the dependency. In general, the stack does not depend to a specific version of BC and you can always use a later version in practice. But, I will update it.