CVE-2023-33252 Information
May 23, 2023
cve
Description
iden3 snarkjs through 0.6.11 allows double spending because there is no validation that the publicSignals length is less than the field modulus.
Reference
https://github.com/iden3/snarkjs/commits/master/src/groth16_verify.js https://github.com/iden3/snarkjs/tags
Share on: