Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Link | Tags |
---|---|
https://github.com/mimblewimble/grin/compare/v3.1.1...v4.0.0 | third party advisory release notes |
https://github.com/mimblewimble/grin-security/blob/master/CVEs/CVE-2020-15899.md | exploit third party advisory patch |