PT-2024-5034 · Bouncy Castle+4 · Bouncy Castle Bc C# .Net+11

David Hook

·

Published

2024-04-22

·

Updated

2026-04-01

·

CVE-2024-29857

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Bouncy Castle Java (BC Java) versions 1.78 and earlier Bouncy Castle Java LTS (BC Java LTS) versions 2.73.6 and earlier Bouncy Castle FIPS Java API (BC-FJA) versions 1.0.2.5 and earlier Bouncy Castle C# .Net versions 2.3.1 and earlier Bamboo Data Center and Server versions prior to 9.2.14, 9.5.4, and 9.6.2 Confluence Data Center and Server versions prior to 7.19.26, 8.5.12, 8.9.4, and 9.0.1
Description: An issue was discovered in ECCurve.java and ECCurve.cs, which can lead to excessive CPU consumption during the evaluation of the curve parameters when importing an EC certificate with crafted F2m parameters. This can allow an unauthenticated attacker to expose assets in the environment susceptible to exploitation, with no impact to confidentiality, no impact to integrity, and high impact to availability, requiring no user interaction.
Recommendations: For Bouncy Castle Java (BC Java) versions 1.78 and earlier, update to version 1.78 or later. For Bouncy Castle Java LTS (BC Java LTS) versions 2.73.6 and earlier, update to version 2.73.6 or later. For Bouncy Castle FIPS Java API (BC-FJA) versions 1.0.2.5 and earlier, update to version 1.0.2.5 or later. For Bouncy Castle C# .Net versions 2.3.1 and earlier, update to version 2.3.1 or later. For Bamboo Data Center and Server versions prior to 9.2.14, 9.5.4, and 9.6.2, upgrade to a release greater than or equal to 9.2.14, 9.5.4, or 9.6.2. For Confluence Data Center and Server versions prior to 7.19.26, 8.5.12, 8.9.4, and 9.0.1, upgrade to a release greater than or equal to 7.19.26, 8.5.12, 8.9.4, or 9.0.1.

Exploit

Fix

Out of bounds Read

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2024-05561
CLEANSTART-2026-IA43044
CVE-2024-29857
GHSA-8XFC-GM6G-VGPV
OPENSUSE-SU-2024:13914-1
OPENSUSE-SU-2025:15739-1
RHSA-2024:5143
RHSA-2024:5144
RHSA-2024:5145
RHSA-2024:5479
RHSA-2024:5481
USN-8108-1

Affected Products

Bamboo
Bamboo Data Center/Server
Bitbucket
Bouncy Castle Bc C# .Net
Bouncy Castle Fips Java Api
Bouncy Castle Bc Java
Bouncy Castle Java Lts
Confluence
Confluence Data Center/Server
Debian
Linuxmint
Ubuntu