Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j55j-52j7-vq87

Опубликовано: 11 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

EPSS

Процентиль: 15%
0.00048
Низкий

7.5 High

CVSS3

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 3.1
ubuntu
почти 3 года назад

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

CVSS3: 3.1
redhat
около 3 лет назад

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

CVSS3: 3.1
nvd
почти 3 года назад

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

CVSS3: 3.1
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 3.1
debian
почти 3 года назад

Non-random values for ticket_age_add in session tickets in crypto/tls ...

EPSS

Процентиль: 15%
0.00048
Низкий

7.5 High

CVSS3

Дефекты

CWE-330