[GO-2022-0531] Session tickets lack random ticket_age_add in crypto/tls

Severity Low
Affected Packages 2
Fixed Packages 2
CVEs 1

An attacker can correlate a resumed TLS session with a previous connection.

Session tickets generated by crypto/tls do not contain a randomly generated
ticket_age_add, which allows an attacker that can observe TLS handshakes to
correlate successive connections by comparing ticket ages during session
resumption.

Package Affected Version
pkg:golang/crypto/tls >= 1.18.2, < 1.17.11
pkg:golang/crypto/tls >= 1.18.2, < 1.18.3
Package Fixed Version
pkg:golang/crypto/tls = 1.17.11
pkg:golang/crypto/tls = 1.18.3
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:golang/crypto/tls crypto tls = 1.17.11
Affected pkg:golang/crypto/tls crypto tls >= 1.18.2 < 1.17.11
Fixed pkg:golang/crypto/tls crypto tls = 1.18.3
Affected pkg:golang/crypto/tls crypto tls >= 1.18.2 < 1.18.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...