{"id":"GHSA-7jjx-3qw9-j6h6","aliases":["RUSTSEC-2024-0392"],"url":"https://o3.security/vulnerability/GHSA-7jjx-3qw9-j6h6","summary":"cggmp21-keygen has ambiguous challenge derivation","details":"Challenge derivation in non-interactive ZK proofs was ambiguous and that could lead to security vulnerability (however, it's unknown if it could be exploited).\n","published":"2024-11-12T20:53:00Z","modified":"2025-10-28T06:29:23.627748Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"cggmp21-keygen","fixedVersion":"0.3.0"}],"fix":{"url":"https://github.com/dfns/cggmp21/pull/103","label":"dfns/cggmp21#103"},"references":[{"type":"WEB","url":"https://github.com/dfns/cggmp21/pull/103"},{"type":"PACKAGE","url":"https://github.com/dfns/cggmp21"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2024-0392.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-10-28T06:29:23.627748Z"}}