CVE-2022-45146
Estado: ModificadaMedia (5.5)—
An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to be zeroed out while still in use by the module, resulting in errors or potential information loss. NOTE: FIPS compliant users are unaffected because the FIPS certification is only for Java 7, 8, and 11.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.43%
- Percentil entre todas las CVEs puntuadas: 35
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-416
Referencias
- https://github.com/bcgit/bc-java/wiki/CVE-2022-45146
- https://mvnrepository.com/artifact/org.bouncycastle/bc-fips
- https://www.bouncycastle.org/latest_releases.html
- https://github.com/bcgit/bc-java/wiki/CVE-2022-45146
- https://mvnrepository.com/artifact/org.bouncycastle/bc-fips
- https://www.bouncycastle.org/latest_releases.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-45146",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2022-11-21T10:15:31.593",
"references": [
{
"url": "https://github.com/bcgit/bc-java/wiki/CVE-2022-45146",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://mvnrepository.com/artifact/org.bouncycastle/bc-fips",
"source": "cve@mitre.org"
},
{
"url": "https://www.bouncycastle.org/latest_releases.html",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/bcgit/bc-java/wiki/CVE-2022-45146",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://mvnrepository.com/artifact/org.bouncycastle/bc-fips",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.bouncycastle.org/latest_releases.html",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-416"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary keys used by the module to be zeroed out while still in use by the module, resulting in errors or potential information loss. NOTE: FIPS compliant users are unaffected because the FIPS certification is only for Java 7, 8, and 11."
},
{
"lang": "es",
"value": "Se descubrió un problema en la API FIPS Java de Bouncy Castle BC-FJA antes de la versión 1.0.2.4. Los cambios en el recolector de basura JVM en Java 13 y versiones posteriores desencadenan un problema en los módulos BC-FJA FIPS donde es posible que las claves temporales utilizadas por el módulo se pongan a cero mientras el módulo aún las usa, lo que genera errores o información potencial. pérdida. NOTA: Los usuarios que cumplen con FIPS no se ven afectados porque la certificación FIPS es solo para Java 7, 8 y 11."
}
],
"lastModified": "2026-06-17T05:09:27.997",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:bouncycastle:fips_java_api:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "326EBBC5-8448-412E-9B9E-6D93A0BD4790",
"versionEndExcluding": "1.0.2.4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:jdk:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9CF0C6F0-395B-4F4A-A950-9967572FCA0F",
"versionStartIncluding": "13.0.0"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}