Injection at org.bouncycastle:bcprov-jdk18on Dependency in Crucible Server

XMLWordPrintable

    • Type: Public Security Vulnerability
    • Resolution: Fixed
    • Priority: Highest
    • 4.9.14
    • Affects Version/s: 4.9.0, 4.9.1, 4.9.2, 4.9.3, 4.9.4, 4.9.5, 4.9.6, 4.9.7, 4.9.8, 4.9.9, 4.9.10, 4.9.11, 4.9.12, 4.9.13
    • Component/s: None
    • 9.3
    • Critical
    • CVE-2026-59650
    • Atlassian (Internal)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber
    • Injection
    • Crucible Data Center, Crucible Server

      This is a vulnerability in a non-Atlassian Crucible Server dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

      This Critical severity Injection vulnerability was introduced in version 4.9.0 of Crucible Server.

      This Injection vulnerability, with a CVSS Score of 9.3 and a CVSS Vector of CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber allows an unauthenticated attacker to modify the actions taken by a system call.

      Atlassian recommends that Crucible Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:

      • Crucible Server 4.9: Upgrade to a release greater than or equal to 4.9.14

      See the release notes (https://confluence.atlassian.com/crucible/crucible-releases-298977378.html). You can download the latest version of Crucible Data Center and Server from the download center (https://www.atlassian.com/software/crucible/download-archives).

      The National Vulnerability Database provides the following description for this vulnerability: In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

              Assignee:
              Unassigned
              Reporter:
              Security Metrics Bot
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: