—
RUSTSEC-2024-0392
Ambiguous challenge derivation
Details
Challenge derivation in non-interactive ZK proofs was ambiguous and that could lead to security vulnerability (however, it's unknown if it could be exploited).
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/cggmp21-keygen
Introduced in:
0.0.0-0Fixed in: 0.3.0Upgrade cggmp21-keygen to 0.3.0 or newer (ecosystem crates.io).