The vendor explicitly identifies these products as affected by this CVE.
- bcmail-jdk18on as a component of Red Hat Fuse 7
- bcmail-jdk18on as a component of Red Hat JBoss Enterprise Application Platform 7
- jboss-eap-7/eap74-els-openjdk11-openshift-rhel8 as a component of Red Hat JBoss Enterprise Application Platform 7
- jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 as a component of Red Hat JBoss Enterprise Application Platform 7
- jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 as a component of Red Hat JBoss Enterprise Application Platform 7
- Summary
- A flaw was found in Bouncy Castle for Java. The S/MIME (Secure/Multipurpose Internet Mail Extensions) validator improperly trusts the signing time asserted by the signer during path validation. This could allow an attacker to bypass certificate path validation, potentially leading to the acceptance of invalid or expired certificates. Such an issue can compromise the integrity of signed data.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
