Use of a Broken or Risky Cryptographic Algorithm Affecting paillier-zk package, versions <0.4.1
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUST-PAILLIERZK-8370177
- published 13 Nov 2024
- disclosed 12 Nov 2024
- credit Unknown
How to fix?
Upgrade paillier-zk
to version 0.4.1 or higher.
Overview
Affected versions of this package are vulnerable to Use of a Broken or Risky Cryptographic Algorithm due to the ambiguous derivation of challenges in non-interactive zero-knowledge proofs. An attacker can potentially compromise the security of the system.