Use of a Broken or Risky Cryptographic Algorithm Affecting cggmp21 package, versions <0.4.1
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUST-CGGMP21-8369586
- published 13 Nov 2024
- disclosed 12 Nov 2024
- credit Unknown
How to fix?
Upgrade cggmp21
to version 0.4.1 or higher.
Overview
Affected versions of this package are vulnerable to Use of a Broken or Risky Cryptographic Algorithm due to the ambiguous handling of challenge derivation in non-interactive ZK proofs. An attacker can potentially exploit this ambiguity to compromise the security of the proofs.