CVE-2020-37268
Last modified
CVE-2020-37268 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type. Applying a functor inlines the body of the parameter, and the inlining drops the record that the term was built under Unset Universe Checking, so the resulting constant carries no trace of the unsafe operation. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type. Applying a functor inlines the body of the parameter, and the inlining drops the record that the term was built under Unset Universe Checking, so the resulting constant carries no trace of the unsafe operation. A module implementation can therefore prove False using a universe inconsistency, expose it through an inlined parameter, and have Print Assumptions report the dependent proof as closed under the global context. Because Print Assumptions is the in-process audit used to confirm that a development rests on no unexpected assumptions, a dependency built this way passes that audit while proving arbitrary propositions. The standalone checker coqchk does reject the resulting compiled file. The project records this in dev/doc/critical-bugs.md under non-fixed bugs and rates the risk as moderate when coqchk is not used.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| rocq-prover | rocq | >= 8.11, <= 9.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2020-37268?
How severe is CVE-2020-37268?
How do I fix CVE-2020-37268?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-37261Rejected reason: This CVE ID has been rejected.
- CVE-2020-37262Rejected reason: This CVE ID has been rejected.
- CVE-2020-37263Rejected reason: This CVE ID has been rejected.
- CVE-2020-37264Rejected reason: This CVE ID has been rejected.
- CVE-2020-37265Rejected reason: This CVE ID has been rejected.
- CVE-2020-37267Renovate versions >=19.180.0 and <23.25.1, when used with Az…7.5
- CVE-2020-3727Adobe Framemaker versions 2019.0.4 and below have an out-of-…8.8
- CVE-2020-37277PocketMine-MP versions before 3.15.4 contain a denial of ser…6.5
- CVE-2020-3728Adobe Framemaker versions 2019.0.4 and below have an out-of-…8.8
- CVE-2020-3729Adobe Framemaker versions 2019.0.4 and below have an out-of-…8.8
- CVE-2020-3730Adobe Framemaker versions 2019.0.4 and below have an out-of-…8.8
- CVE-2020-3731Adobe Framemaker versions 2019.0.4 and below have a heap ove…8.8
Are you affected by CVE-2020-37268?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
