question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Vulnerability in BouncyCastle

See original GitHub issue

Hello,

recently we saw this: https://github.com/bcgit/bc-csharp/wiki/CVE-2020-15522 Looks like packages before BC C# .NET 1.8.6 or earlier are affected.

Can you update the code to use the latest? https://github.com/vivet/GoogleApi/blob/a0b4dab987df546bc58b815382f85c7c4b7dd722/GoogleApi/GoogleApi.csproj#L105-L108

Thank you

Issue Analytics

  • State:closed
  • Created 2 years ago
  • Comments:15 (7 by maintainers)

github_iconTop GitHub Comments

1reaction
vivetcommented, Nov 8, 2021

I have fixed the issue and published an updated NuGet. It turned out that it was the continuous integration, that doesn’t create the NuGet package correctly. So, I manually published a version where the dependencies are correct.

Let me know if you have further issues.

0reactions
eddynakacommented, Nov 8, 2021

Thanks. The package seems correct. 😃

Read more comments on GitHub >

github_iconTop Results From Across the Web

Bouncycastle : Security Vulnerabilities
The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate validation ...
Read more >
Bouncy Castle crypto authentication bypass vulnerability ...
A severe authentication bypass vulnerability has been reported in Bouncy Castle, a popular open-source cryptography library.
Read more >
bouncycastle vulnerabilities
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Read more >
Bouncycastle - Security Vulnerabilities in 2023 - stack.watch
In 2023 there have been 1 vulnerability in Bouncycastle with an average score of 5.3 out of ten. Bouncycastle did not have any...
Read more >
Bouncy Castle and the Impact of Cryptographic Vulnerabilities
The Bouncy Castle vulnerability was a flaw in the implementation of the OpenBSDBcrypt.doCheckPassword() function.
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found