File tree 2 files changed +10
-11
lines changed
2 files changed +10
-11
lines changed Original file line number Diff line number Diff line change 7
7
" CVE-2024-45039" ,
8
8
" GHSA-q3hw-3gm4-w5cr"
9
9
],
10
- "summary" : " gnark's Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark" ,
11
- "details" : " gnark's Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark" ,
10
+ "summary" : " Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark" ,
11
+ "details" : " Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark" ,
12
12
"affected" : [
13
13
{
14
14
"package" : {
35
35
{
36
36
"type" : " ADVISORY" ,
37
37
"url" : " https://github.com/Consensys/gnark/security/advisories/GHSA-q3hw-3gm4-w5cr"
38
- },
39
- {
40
- "type" : " ADVISORY" ,
41
- "url" : " https://nvd.nist.gov/vuln/detail/CVE-2024-45039"
42
38
}
43
39
],
44
40
"database_specific" : {
45
41
"url" : " https://pkg.go.dev/vuln/GO-2024-3122" ,
46
- "review_status" : " UNREVIEWED "
42
+ "review_status" : " REVIEWED "
47
43
}
48
44
}
Original file line number Diff line number Diff line change @@ -4,15 +4,18 @@ modules:
4
4
versions :
5
5
- fixed : 0.11.0
6
6
vulnerable_at : 0.10.0
7
- summary : gnark's Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark
7
+ summary : |-
8
+ Groth16 commitment extension unsound for more than one commitment in
9
+ github.com/consensys/gnark
8
10
cves :
9
11
- CVE-2024-45039
10
12
ghsas :
11
13
- GHSA-q3hw-3gm4-w5cr
12
14
references :
13
15
- advisory : https://github.com/Consensys/gnark/security/advisories/GHSA-q3hw-3gm4-w5cr
14
- - advisory : https://nvd.nist.gov/vuln/detail/CVE-2024-45039
16
+ notes :
17
+ - The fix mentioned in the advisory (https://github.com/Consensys/gnark/commit/e7c66b000454f4d2a4ae48c005c34154d4cfc2a2) does not exist, and I was not able to locate the real fix.
15
18
source :
16
19
id : GHSA-q3hw-3gm4-w5cr
17
- created : 2024-11-12T11:30:11.924411 -05:00
18
- review_status : NEEDS_REVIEW
20
+ created : 2024-12-12T14:10:57.751829 -05:00
21
+ review_status : REVIEWED
You can’t perform that action at this time.
0 commit comments