mimblewimble/grin

mimblewimble/grin

Releases75
Frequency1 month 1 week
Last Release
Stars5.09K
Minimal implementation of the Mimblewimble protocol.

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble.

5.3 MEDIUM5 MEDIUM

Grin before 3.1.0 allows attackers to adversely affect availability of data on a Mimblewimble blockchain.

7.5 HIGH5 MEDIUM

Grin through 2.1.1 has Insufficient Validation.

9.8 CRITICAL7.5 HIGH

util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory traversal in a ZIP archive.