Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qj3v-q2vj-4c8h

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Calculation error in ark-r1cs-std

An issue was discovered in the ark-r1cs-std crate before 0.3.1 for Rust. It does not enforce any constraints in the FieldVar::mul_by_inverse method. Thus, a prover can produce a proof that is unsound but is nonetheless verified.

Пакеты

Наименование

ark-r1cs-std

rust
Затронутые версииВерсия исправления

>= 0.2.0, < 0.3.1

0.3.1

EPSS

Процентиль: 58%
0.00363
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-682

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

An issue was discovered in the ark-r1cs-std crate before 0.3.1 for Rust. It does not enforce any constraints in the FieldVar::mul_by_inverse method. Thus, a prover can produce a proof that is unsound but is nonetheless verified.

EPSS

Процентиль: 58%
0.00363
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-682