PT-2024-40460 · Crates.Io · Cggmp21

Published

2024-11-12

·

Updated

2024-11-12

CVSS v4.0

2.7

Low

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions No specific software or versions mentioned.
Description The issue concerns challenge derivation in non-interactive Zero-Knowledge (ZK) proofs, which was ambiguous and could potentially lead to a security issue. However, it is unknown if this ambiguity could be exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

GHSA-RM66-9GH4-4GP8

Affected Products

Cggmp21