Junglewise Threat Intelligence

CVE-2024-21670: CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credential

CVE-2024-21670 · Severity: low · CVSS 3.1 · Published 2024-01-16

Technologies: ursa (crates.io), anoncreds-clsignatures (crates.io). Vendors: crates.io.

Executive brief

CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credential

Affected products

  • crates.io ursa
  • crates.io anoncreds-clsignatures

Related threats