{"id":"CVE-2022-47931","aliases":["GO-2023-1904"],"url":"https://o3.security/vulnerability/CVE-2022-47931","summary":"Collision of hash values in github.com/bnb-chain/tss-lib","details":"IO FinNet tss-lib before 2.0.0 allows a collision of hash values.","published":"2022-12-23T00:30:23Z","modified":"2024-05-22T19:01:52Z","cvss":{"score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/bnb-chain/tss-lib","fixedVersion":"1.3.6-0.20230324145555-bb6fb30bd3eb"}],"fix":{"url":"https://github.com/bnb-chain/tss-lib/pull/233","label":"bnb-chain/tss-lib#233"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-47931"},{"type":"WEB","url":"https://github.com/bnb-chain/tss-lib/pull/233"},{"type":"WEB","url":"https://github.com/IoFinnet/threshlib/commit/369ec50be1437588a9733443bcb2f15b794601d4"},{"type":"WEB","url":"https://github.com/bnb-chain/tss-lib/commit/bb6fb30bd3ebd35c755109836aa1a5ee6126c8a0"},{"type":"WEB","url":"https://github.com/IoFinnet/threshlib/releases/tag/v2.0.0"},{"type":"PACKAGE","url":"https://github.com/bnb-chain/tss-lib"},{"type":"WEB","url":"https://github.com/golang/vulndb/blob/master/data/reports/GO-2023-1904.yaml"},{"type":"WEB","url":"https://medium.com/@iofinnet/security-disclosure-for-ecdsa-and-eddsa-threshold-signature-schemes-4e969af7155b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-05-22T19:01:52Z"}}