CVE-2023-45287
Before Go 1.20, the RSA based key exchange methods in crypto/tls may exhibit a timing side channel
7.5
HIGH
CVSS 3.1
EPSS 1.3%
描述
Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.
如何修補 CVE-2023-45287
要修補 CVE-2023-45287,請將受影響套件升級到下列已修補版本。
- —升級至 1.20.0 或更新版本
- —未列出修補版本
- —未列出修補版本
- —升級至 1.20.0 或更新版本
CVE-2023-45287 正在被利用嗎?
低 — EPSS 為 1.3%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- from 0, < 1.20.0
- from 0
- from 0
- from 0, < 1.20.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |