QID 996749

Date Published: 2024-01-17

QID 996749: Rust (Rust) Security Update for anoncreds-clsignatures (GHSA-2q6j-gqc4-4gw3)

A weakness in the Hyperledger AnonCreds specification that is not mitigated in the Ursa and AnonCreds implementations is that the Issuer does not publish a key correctness proof demonstrating that a generated private key is sufficient to meet the unlinkability guarantees of AnonCreds. A sufficient private key is one in which it's components p and q are safe primes, such that:

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-2q6j-gqc4-4gw3 for updates and patch information.
    Vendor References

    CVEs related to QID 996749

    Software Advisories
    Advisory ID Software Component Link