{"id":"GHSA-rm66-9gh4-4gp8","aliases":["RUSTSEC-2024-0393"],"url":"https://o3.security/vulnerability/GHSA-rm66-9gh4-4gp8","summary":"cggmp21 vulnerable to ambiguous challenge derivation","details":"Challenge derivation in non-interactive ZK proofs was ambiguous and that could lead to security vulnerability (however, it's unknown if it could be exploited).\n","published":"2024-11-12T20:54:58Z","modified":"2025-10-28T06:29:26.069465Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"cggmp21","fixedVersion":"0.4.0"}],"fix":{"url":"https://github.com/dfns/cggmp21/pull/103","label":"dfns/cggmp21#103"},"references":[{"type":"WEB","url":"https://github.com/dfns/cggmp21/pull/103"},{"type":"PACKAGE","url":"https://github.com/LFDT-Lockness/cggmp21"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2024-0393.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-10-28T06:29:26.069465Z"}}