-
Notifications
You must be signed in to change notification settings - Fork 330
Closed as not planned
Labels
bugunintended behaviour in ecdsa codeunintended behaviour in ecdsa code
Description
Hello,
SNYK and other scanning tools alerts on package vulnerability ( Timing Attack ) found at "sign_digest" API function.
( ecdsa.SigningKey.sign_digest() )
https://www.cve.org/CVERecord?id=CVE-2024-23342( HIGH Alert)
Can you address when you are going to fix this?
Regards,
Yaron
maksimu, augi and eshgovil
Metadata
Metadata
Assignees
Labels
bugunintended behaviour in ecdsa codeunintended behaviour in ecdsa code