Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j55j-52j7-vq87

Опубликовано: 11 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

EPSS

Процентиль: 55%
0.0088
Низкий

7.5 High

CVSS3

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 3.1
ubuntu
почти 4 года назад

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

CVSS3: 3.1
redhat
около 4 лет назад

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

CVSS3: 3.1
nvd
почти 4 года назад

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

CVSS3: 3.1
msrc
4 месяца назад

Session tickets lack random ticket_age_add in crypto/tls

CVSS3: 3.1
debian
почти 4 года назад

Non-random values for ticket_age_add in session tickets in crypto/tls ...

EPSS

Процентиль: 55%
0.0088
Низкий

7.5 High

CVSS3

Дефекты

CWE-330