CVE-2022-30629

LOW

Go <1.17.11, 1.18.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

Scores

CVSS v3 3.1
EPSS 0.0007
EPSS Percentile 20.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-330
Status published
Products (1)
golang/go < 1.17.11
Published Aug 10, 2022
Tracked Since Feb 18, 2026