CVE Vulnerabilities

CVE-2023-33252

Published: May 21, 2023 | Modified: Jan 21, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.

Affected Software

NameVendorStart VersionEnd Version
Snarkjs0kims*0.6.11 (including)

References