CVE Vulnerabilities

CVE-2023-33252

Published: May 21, 2023 | Modified: May 30, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.

Affected Software

Name Vendor Start Version End Version
Snarkjs 0kims * 0.6.11 (including)

References