Логотип exploitDog
bind:CVE-2024-22192
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-22192

Количество 2

Количество 2

nvd логотип

CVE-2024-22192

около 2 лет назад

Ursa is a cryptographic library for use with blockchains. The revocation scheme that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model. Notably, a malicious verifier may be able to generate a unique identifier for a holder providing a verifiable presentation that includes a Non-Revocation proof. The impact of the flaw is that a malicious verifier may be able to determine a unique identifier for a holder presenting a Non-Revocation proof. Ursa has moved to end-of-life status and no fix is expected.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6698-mhxx-r84g

около 2 лет назад

Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holders

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-22192

Ursa is a cryptographic library for use with blockchains. The revocation scheme that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model. Notably, a malicious verifier may be able to generate a unique identifier for a holder providing a verifiable presentation that includes a Non-Revocation proof. The impact of the flaw is that a malicious verifier may be able to determine a unique identifier for a holder presenting a Non-Revocation proof. Ursa has moved to end-of-life status and no fix is expected.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-6698-mhxx-r84g

Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holders

CVSS3: 6.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу