Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Minerva attack vulnerability #352

Closed
prasadayush opened this issue Jan 30, 2025 · 1 comment
Closed

Minerva attack vulnerability #352

prasadayush opened this issue Jan 30, 2025 · 1 comment

Comments

@prasadayush
Copy link

The ecdsa PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior are vulnerable to the Minerva attack. As of time of publication, no known patched version exists.

Below are the risk factors associated to this issue -
Attack vector: network, High severity, Package in use

Vulnerability link - https://nvd.nist.gov/vuln/detail/CVE-2024-23342

@tomato42
Copy link
Member

duplicate of #330

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants