The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade orchard to version 0.14.0 or higher.
Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity in the assign_advice process. An attacker can bypass circuit soundness and authorize unauthorized spends or double-spend notes by providing crafted private circuit inputs that exploit the lack of constraints on the base value. This allows repeated spending of the same note with distinct nullifiers or unauthorized spending of existing notes if the attacker knows the corresponding incoming viewing key. Exploitation is undetectable on-chain and only requires setting specific private inputs.