CVE-2022-30629

3.1 LOW
Published: August 10, 2022 Modified: March 06, 2026
View on NVD

Description

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://go.dev/cl/405994
Source: security@golang.org
Patch
https://go.dev/issue/52814
Source: security@golang.org
Exploit Issue Tracking Vendor Advisory
https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ
Source: security@golang.org
Mailing List Vendor Advisory
https://pkg.go.dev/vuln/GO-2022-0531
Source: security@golang.org
Vendor Advisory
https://go.dev/cl/405994
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
https://go.dev/issue/52814
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Issue Tracking Vendor Advisory
https://go.googlesource.com/go/+/fe4de36198794c447fbd9d7cc2d7199a506c76a5
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Patch
https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Vendor Advisory
https://pkg.go.dev/vuln/GO-2022-0531
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

10 reference(s) from NVD

Quick Stats

CVSS v3 Score
3.1 / 10.0
EPSS (Exploit Probability)
0.1%
20th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

golang