Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15899
Reference (s):
- https://github.com/mimblewimble/grin-security/blob/master/CVEs/CVE-2020-15899.md
- https://github.com/mimblewimble/grin/compare/v3.1.1 v4.0.0