Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-30629


Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.


Published

2022-08-10T20:15:40.560

Last Modified

2024-11-21T07:03:03.717

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.1 (LOW)

Weaknesses
  • Type: Primary
    CWE-330

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application golang go < 1.17.11 Yes
Application golang go < 1.18.3 Yes

References