{"id":"CVE-2020-12118","aliases":["GHSA-399h-cmvp-qgx5","GO-2022-0769"],"url":"https://o3.security/vulnerability/CVE-2020-12118","summary":"Incorrect Default Permissions in Binance tss-lib","details":"The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information from other parties.","published":"2020-04-23T22:15:12.913Z","modified":"2026-08-27T08:15:08.182386Z","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"github.com/binance-chain/tss-lib","fixedVersion":"1.2.0"}],"fix":{"url":"https://github.com/binance-chain/tss-lib/pull/89","label":"binance-chain/tss-lib#89"},"references":[{"type":"ADVISORY","url":"https://github.com/binance-chain/tss-lib/releases/tag/v1.2.0"},{"type":"FIX","url":"https://github.com/binance-chain/tss-lib/pull/89"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T08:15:08.182386Z"}}