Overview
About vulnerability
A flaw was found in CIRCL’s implementation of the FourQ elliptic curve. This vulnerability allows an attacker to compromise session security via low-order point injection and incorrect point validation during Diffie-Hellman key exchange.Details
- Affected product:
- Grafana , ProtonMail/go-crypto , argocd , cloudflare/circl , github.com/ProtonMail/go-crypto , github.com/cloudflare/circl , go-git/go-git
- Affected packages:
- github.com/cloudflare/circl @ 1.3.7 (+12 more)