{"id":"GHSA-978j-88f3-p5j3","aliases":["RUSTSEC-2020-0160"],"url":"https://o3.security/vulnerability/GHSA-978j-88f3-p5j3","summary":"Threshold value is ignored (all shares are n=3)","details":"Affected versions of this crate did not properly calculate secret shares requirements.\n\nThis reduces the security of the algorithm by restricting the crate to always\nusing a threshold value of three, rather than a configurable limit.\n\nThe flaw was corrected by correctly configuring the threshold.\n","published":"2022-06-17T00:18:43Z","modified":"2023-11-08T04:17:45.856172Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"shamir","fixedVersion":"2.0.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Nebulosus/shamir/issues/3"},{"type":"PACKAGE","url":"https://github.com/Nebulosus/shamir"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2020-0160.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:17:45.856172Z"}}