First published: Thu Dec 22 2022(Updated: )
IO FinNet tss-lib before 2.0.0 allows a collision of hash values.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/bnb-chain/tss-lib | <1.3.6-0.20230324145555-bb6fb30bd3eb | 1.3.6-0.20230324145555-bb6fb30bd3eb |
Binance TSS-lib | <2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-47931 is classified as a moderate severity vulnerability due to its potential to cause hash collisions.
CVE-2022-47931 allows an attacker to exploit hash collisions, leading to potential security flaws in applications using the vulnerable version of tss-lib.
To fix CVE-2022-47931, upgrade tss-lib to version 2.0.0 or later.
CVE-2022-47931 affects all versions of tss-lib prior to 2.0.0.
CVE-2022-47931 is not considered critical, but it should still be addressed promptly due to its impact on cryptographic processes.