Vulnerability Report: GO-2024-3123
- CVE-2024-45040, GHSA-9xcg-3q8v-7fq6
- Affects: github.com/consensys/gnark
- Published: Sep 13, 2024
Commitments to private witnesses in Groth16 as implemented break zero-knowledge property in github.com/consensys/gnark
For detailed information about this vulnerability, visit https://github.com/Consensys/gnark/security/advisories/GHSA-9xcg-3q8v-7fq6.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.11.0
-
before v0.11.0
1 unexported affected symbols
- builder.Commit
Aliases
References
- https://github.com/Consensys/gnark/security/advisories/GHSA-9xcg-3q8v-7fq6
- https://github.com/Consensys/gnark/commit/afda68a38acca37becb8ba6d8982d03fee9559a0
- https://github.com/Consensys/gnark/pull/1245
- https://vuln.go.dev/ID/GO-2024-3123.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.