CVE Vulnerabilities

CVE-2023-33252

Published: May 21, 2023 | Modified: Jan 21, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.

Affected Software

Name Vendor Start Version End Version
Snarkjs 0kims * 0.6.11 (including)

References