Known Vulnerabilities for products from Consensys
Listed below are 3 of the newest known vulnerabilities associated with the vendor "Consensys".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2024-23688 json | Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be uniq... | Not Provided | 2024-01-19 | 2026-07-14 |
| CVE-2023-44378 json | gnark is a zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.9.0, for some in-circuit valu... | 5.5 - MEDIUM | 2023-10-09 | 2023-10-13 |
| CVE-2023-44273 json | Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA s... | 9.8 - CRITICAL | 2023-09-28 | 2023-10-02 |