Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
2022-08-10T20:15:40.560
2024-11-21T07:03:03.717
Modified
CVSSv3.1: 3.1 (LOW)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | golang | go | < 1.17.11 | Yes |
| Application | golang | go | < 1.18.3 | Yes |