CVE-2022-30629

LOW3.1EPSS 0.07%

Session tickets lack random ticket_age_add in crypto/tls

發布日:2022/7/28修改日:2026/4/28

描述

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1LOW3.1CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

參考連結(7)