The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information from other parties.
github.com/binance-chain/tss-lib/ecdsa/keygen
{
"nvd_published_at": null,
"severity": "HIGH",
"github_reviewed_at": "2021-05-25T20:16:35Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-276"
]
}