Lucene search

K
cvelistGitHub_MCVELIST:CVE-2024-21670
HistoryJan 16, 2024 - 9:44 p.m.

CVE-2024-21670 CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credential

2024-01-1621:44:05
CWE-327
GitHub_M
www.cve.org
3
ursa
cl-signatures
revocation scheme
flaw
anoncreds
verifier
privacy guarantees
cryptographic library

CVSS3

6.5

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

39.1%

Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model, allowing a malicious holder of a revoked credential to generate a valid Non-Revocation Proof for that credential as part of an AnonCreds presentation. A verifier may verify a credential from a holder as being “not revoked” when in fact, the holder’s credential has been revoked. Ursa has moved to end-of-life status and no fix is expected.

CNA Affected

[
  {
    "vendor": "hyperledger-archives",
    "product": "ursa",
    "versions": [
      {
        "version": "<= 0.3.7",
        "status": "affected"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

PHYSICAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

39.1%

Related for CVELIST:CVE-2024-21670