The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information from other parties.
github.com/binance-chain/tss-lib/ecdsa/keygen
{ "nvd_published_at": null, "cwe_ids": [ "CWE-276" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-05-25T20:16:35Z" }