CVE-2022-30629
Vulnerability Summary
Timeline
Description
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
CVSS Metrics
- v3.1•LOW•Score: 3.1CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Trends
Current EPSS score: 1.08%• Percentile: 64%
Techniques & Countermeasures
- CWE-330•Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Affected Systems
- debian•golang-1.15
all
- go standard library•crypto/tls
< 1.17.11 | ≥ 1.18.0-0, < 1.18.3
- golang•go
< 1.17.11 | ≥ 1.18.0, < 1.18.3
- Go•stdlib
≥ 1.18.0-0, < 1.18.3
- redhat•butane
< 0:0.15.0-2.rhaos4.11.el8
- redhat•butane-debuginfo
< 0:0.15.0-2.rhaos4.11.el8
- redhat•butane-debugsource
< 0:0.15.0-2.rhaos4.11.el8
- redhat•butane-redistributable
< 0:0.15.0-2.rhaos4.11.el8
- redhat•cri-o
< 0:1.24.2-4.rhaos4.11.gitd6283df.el8
- redhat•cri-o-debuginfo
< 0:1.24.2-4.rhaos4.11.gitd6283df.el8
- redhat•cri-o-debugsource
< 0:1.24.2-4.rhaos4.11.gitd6283df.el8
- redhat•cri-tools
< 0:1.24.2-6.el8
- redhat•cri-tools-debuginfo
< 0:1.24.2-6.el8
- redhat•cri-tools-debugsource
< 0:1.24.2-6.el8
- redhat•ignition
< 0:2.14.0-4.rhaos4.11.el8
- redhat•ignition-debuginfo
< 0:2.14.0-4.rhaos4.11.el8
- redhat•ignition-debugsource
< 0:2.14.0-4.rhaos4.11.el8
- redhat•ignition-validate
< 0:2.14.0-4.rhaos4.11.el8
- redhat•ignition-validate-debuginfo
< 0:2.14.0-4.rhaos4.11.el8
References (16)
- https://go.dev/cl/405994
- https://go.googlesource.com/go/+/fe4de36198794c447fbd9d7cc2d7199a506c76a5
- https://go.dev/issue/52814
- https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ
- https://pkg.go.dev/vuln/GO-2022-0531
- https://access.redhat.com/errata/RHSA-2022:6102
- https://access.redhat.com/security/updates/classification/#low
- https://bugzilla.redhat.com/show_bug.cgi?id=2092793
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6102.json
- https://access.redhat.com/security/cve/CVE-2022-30629
- https://www.cve.org/CVERecord?id=CVE-2022-30629
- https://nvd.nist.gov/vuln/detail/CVE-2022-30629
- https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg
- https://access.redhat.com/errata/RHSA-2022:6535
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6535.json
- https://security-tracker.debian.org/tracker/CVE-2022-30629