CVE-2024-21670

Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model, allowing a malicious holder of a revoked credential to generate a valid Non-Revocation Proof for that credential as part of an AnonCreds presentation. A verifier may verify a credential from a holder as being "not revoked" when in fact, the holder's credential has been revoked. Ursa has moved to end-of-life status and no fix is expected.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hyperledger:ursa:0.1.0:*:*:*:*:rust:*:*

History

24 Jan 2024, 18:14

Type Values Removed Values Added
CPE cpe:2.3:a:hyperledger:ursa:0.1.0:*:*:*:*:rust:*:*
First Time Hyperledger
Hyperledger ursa
References () https://github.com/hyperledger-archives/ursa/security/advisories/GHSA-r78f-4q2q-hvv4 - () https://github.com/hyperledger-archives/ursa/security/advisories/GHSA-r78f-4q2q-hvv4 - Vendor Advisory
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 8.1
Summary
  • (es) Ursa es una librería criptográfica para usar con blockchains. El esquema de revocación que forma parte de las implementaciones de Ursa CL-Signatures tiene un fallo que podría afectar las garantías de privacidad definidas por el modelo de credencial verificable de AnonCreds, permitiendo a un titular malicioso de una credencial revocada generar una prueba de no revocación válida para esa credencial como parte de una presentación de AnonCreds. Un verificador puede verificar que una credencial de un titular está "not revoked" cuando, en realidad, la credencial del titular ha sido revocada. Ursa ha pasado al estado de fin de vida útil y no se espera ninguna solución.

16 Jan 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-16 22:15

Updated : 2024-01-24 18:14


NVD link : CVE-2024-21670

Mitre link : CVE-2024-21670

CVE.ORG link : CVE-2024-21670


JSON object : View

Products Affected

hyperledger

  • ursa
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm