Описание
Double spend in snarkjs
iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.
Пакеты
Наименование
snarkjs
npm
Затронутые версииВерсия исправления
<= 0.6.11
Отсутствует
Связанные уязвимости
CVSS3: 7.5
nvd
больше 2 лет назад
iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.