PT-2020-13046 · Binance · Tss-Lib

CVE-2020-12118

·

Published

2020-04-23

·

Updated

2024-08-21

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Binance tss-lib versions prior to 1.2.0
Description The keygen protocol implementation in Binance tss-lib allows attackers to generate crafted h1 and h2 parameters, which can compromise a signing round or obtain sensitive information from other parties. This issue is related to incorrect default permissions in the library.
Recommendations For versions prior to 1.2.0, update to version 1.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the keygen protocol implementation to minimize the risk of exploitation. Avoid using the h1 and h2 parameters in sensitive operations until the issue is resolved.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12118
GHSA-399H-CMVP-QGX5
GO-2022-0769

Affected Products

Tss-Lib