The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for extracting a private key.
References
Configurations
No configuration.
History
29 Jul 2025, 14:14
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
28 Jul 2025, 03:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-497 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.9 |
28 Jul 2025, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-28 02:15
Updated : 2025-07-29 14:14
NVD link : CVE-2022-50237
Mitre link : CVE-2022-50237
CVE.ORG link : CVE-2022-50237
JSON object : View
Products Affected
No product.
CWE
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere