Skip to content

Security fix#49

Merged
survived merged 10 commits into
mfrom
release-fix
Jul 18, 2024
Merged

Security fix#49
survived merged 10 commits into
mfrom
release-fix

Conversation

@survived
Copy link
Copy Markdown
Contributor

Challenge derivation in non-interactive ZK proofs was ambiguous and that could lead to security vulnerability (however, it's unknown if it could be exploited). This PR makes challenge derivation unambiguous.

The fix was developed and reviewed privately. Fixed library version has been already released on crates.io.

@survived
Copy link
Copy Markdown
Contributor Author

Github deploy workflow was canceled, as I released the new library version to crates.io manually

@survived survived merged commit 06e2159 into m Jul 18, 2024
@survived survived deleted the release-fix branch July 18, 2024 09:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants