CVE-2024-21670

MEDIUM
Published Jan 16, 2024 Modified Nov 21, 2024 CWE-327

Description

Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model, allowing a malicious holder of a revoked credential to generate a valid Non-Revocation Proof for that credential as part of an AnonCreds presentation. A verifier may verify a credential from a holder as being "not revoked" when in fact, the holder's credential has been revoked. Ursa has moved to end-of-life status and no fix is expected.

Is your site exposed to CVE-2024-21670?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

6.5
MEDIUM
CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N

Weakness Type (CWE)

CWE-327 CWE-327

Affected Products

Vendor Product
hyperledger ursa

References

Frequently Asked Questions

What is CVE-2024-21670? +
Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model, allowing a malicious holder of a revoked credential to generate a valid Non-Revocation Proof for that credential as part of an AnonCreds presentation. A verifier may verify a credential from a holder as being "not revoked" when in fact, the holder's credential has been revoked. Ursa has moved to end-of-life status and no fix is expected. It has a CVSS v3.1 base score of 6.5 (MEDIUM).
How severe is CVE-2024-21670? +
CVE-2024-21670 has a CVSS v3.1 score of 6.5 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2024-21670? +
CVE-2024-21670 affects products from hyperledger, specifically: ursa. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-21670? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-21670 — free, no signup required.