CVE-2022-30629

LOW3.1EPSS 0.07%

Session tickets lack random ticket_age_add in crypto/tls

Published: 7/28/2022Modified: 4/28/2026

Description

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1LOW3.1CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

References (7)