The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information from other parties.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/binance-chain/tss-lib(Go) | 0 | 1.2.0 | N/A |
CVSS Metrics