crates.io package
grin
pkg:cargo/grin
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-15899 | Hig | 7.5 | >= 3.0.0, < 4.0.0 | 4.0.0 | Jul 28, 2020 | Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble. | |
| CVE-2020-12439 | Med | 5.3 | < 3.1.0 | 3.1.0 | May 5, 2020 | Grin before 3.1.0 allows attackers to adversely affect availability of data on a Mimblewimble blockchain. | |
| CVE-2020-6638 | Hig | 7.5 | < 3.0.0 | 3.0.0 | Jan 21, 2020 | Grin through 2.1.1 has Insufficient Validation. |
- affected >= 3.0.0, < 4.0.0fixed 4.0.0
Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble.
- affected < 3.1.0fixed 3.1.0
Grin before 3.1.0 allows attackers to adversely affect availability of data on a Mimblewimble blockchain.
- affected < 3.0.0fixed 3.0.0
Grin through 2.1.1 has Insufficient Validation.