mimblewimble/grin

mimblewimble/grin

Releases77
Frequency1 month 1 week
Last Release
Stars5.09K
Minimal implementation of the Mimblewimble protocol.

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
>= 3.0.0, < 4.0.07.5 HIGH5 MEDIUM

Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble.

< 3.1.05.3 MEDIUM5 MEDIUM

Grin before 3.1.0 allows attackers to adversely affect availability of data on a Mimblewimble blockchain.

<= 2.1.1, < 3.0.07.5 HIGH5 MEDIUM

Grin through 2.1.1 has Insufficient Validation.

< 1.0.29.8 CRITICAL7.5 HIGH

util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory traversal in a ZIP archive.