You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
David Hook edited this page Aug 3, 2026
·
2 revisions
Title:* LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
Issue affecting: BC before 1.85.
Fixed versions: BC 1.85.
Platform affected: Java 8 and later.
The CVE-2023-33201 / CVE-2026-0636 fix added filterEncode() escaping to the main-java X509LDAPCertStoreSpi, main-java LDAPStoreHelper, and jdk1.4 X509LDAPCertStoreSpi, but missed the jdk1.4 LDAPStoreHelper. Its parseDN() returns the raw DN component, which callers concatenate directly into '(' + attr + '=' + value + ')' and pass to DirContext.search(). Because ant/jdk14.xml overwrites the patched main-java file with this variant when building bcprov-jdk14, the advertised fix never reaches the jdk14 distribution. An attacker who can present a certificate with a crafted Subject/Issuer CN (e.g.