CVE-2024-21670
CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credential
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model, allowing a malicious holder of a revoked credential to generate a valid Non-Revocation Proof for that credential as part of an AnonCreds presentation. A verifier may verify a credential from a holder as being "not revoked" when in fact, the holder's credential has been revoked. Ursa has moved to end-of-life status and no fix is expected.
Ursa es una librería criptográfica para usar con blockchains. El esquema de revocación que forma parte de las implementaciones de Ursa CL-Signatures tiene un fallo que podría afectar las garantías de privacidad definidas por el modelo de credencial verificable de AnonCreds, permitiendo a un titular malicioso de una credencial revocada generar una prueba de no revocación válida para esa credencial como parte de una presentación de AnonCreds. Un verificador puede verificar que una credencial de un titular está "not revoked" cuando, en realidad, la credencial del titular ha sido revocada. Ursa ha pasado al estado de fin de vida útil y no se espera ninguna solución.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-12-29 CVE Reserved
- 2024-01-16 CVE Published
- 2024-01-25 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/hyperledger-archives/ursa/security/advisories/GHSA-r78f-4q2q-hvv4 | 2024-01-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hyperledger Search vendor "Hyperledger" | Ursa Search vendor "Hyperledger" for product "Ursa" | 0.1.0 Search vendor "Hyperledger" for product "Ursa" and version "0.1.0" | rust |
Affected
|