github.com/binance-chain/tss-lib

govv1.3.5

Threshold Signature Scheme, for ECDSA and EDDSA

10 versions23 maintainers0 deps1,009 weekly dl
binance-chain/tss-lib
25
/ 100
Health
do not use

github.com/binance-chain/tss-lib has critical vulnerabilities — do not use

Update to >= 1.3.6-0.20230324145555-bb6fb30bd3eb to fix known vulnerabilities

  • Low health score (25/100)
  • 1 high severity vulnerabilities
  • 1 critical vulnerabilities
Health breakdown0 – 100
0/25
maintenance
6/20
popularity
8/25
security
6/15
maturity
5/15
community
Vulnerabilities
7
1 critical1 high1 medium4 low
Advisories (7)
SeverityIDSummaryFixed in
criticalCVE-2023-26556IO FinNet tss-lib vulnerable to timing attack from non-constant time scalar multiplication2.0.0
mediumCVE-2022-47930IO FinNet tss-lib vulnerable to replay attacks involving proofs2.0.0
highCVE-2023-26557IO FinNet tss-lib vulnerable to timing attack from non-constant time scalar arithmetic1.3.6-0.20230324145555-bb6fb30bd3eb
unknownCVE-2023-26556Timing attack from non-constant time scalar multiplication in github.com/bnb-chain/tss-lib1.3.6-0.20230324145555-bb6fb30bd3eb
unknownCVE-2023-26557Timing attack from non-constant time scalar arithmetic in github.com/bnb-chain/tss-lib1.3.6-0.20230324145555-bb6fb30bd3eb
unknownCVE-2022-47930Replay attacks involving proofs in github.com/bnb-chain/tss-lib
unknownCVE-2022-47931Collision of hash values in github.com/bnb-chain/tss-lib1.3.6-0.20230324145555-bb6fb30bd3eb

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/go/github.com/binance-chain/tss-lib

Last updated · 2022-09-23T02:44:11Z

github.com/binance-chain/tss-lib — Health Score 25/100 | DepScope