Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-52460 Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
Ubuntu USN Ubuntu USN USN-6038-1 Go vulnerabilities
Ubuntu USN Ubuntu USN USN-6038-2 Go vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 18 Jun 2025 00:45:00 +0900

Type Values Removed Values Added
First Time appeared Redhat stf
CPEs cpe:/a:redhat:service_telemetry_framework:1.5::el8 cpe:/a:redhat:stf:1.5::el8
Vendors & Products Redhat service Telemetry Framework
Redhat stf

Mon, 09 Sep 2024 03:45:00 +0900

Type Values Removed Values Added
First Time appeared Redhat multicluster Engine
CPEs cpe:/a:redhat:acm:2.4::el8
cpe:/a:redhat:acm:2.5::el8
cpe:/a:redhat:acm:2.6::el8
cpe:/a:redhat:multicluster_engine:2.1::el8
Vendors & Products Redhat multicluster Engine

Tue, 20 Aug 2024 07:15:00 +0900

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.4::el8
cpe:/a:redhat:acm:2.5::el8
cpe:/a:redhat:acm:2.6::el8
cpe:/a:redhat:multicluster_engine:2.1::el8
Vendors & Products Redhat multicluster Engine

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2024-08-03T06:56:13.230Z

Reserved: 2022-05-12T00:00:00

Link: CVE-2022-30629

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-10T20:15:40.560

Modified: 2024-11-21T07:03:03.717

Link: CVE-2022-30629

cve-icon Redhat

Severity : Low

Publid Date: 2022-06-02T00:00:00Z

Links: CVE-2022-30629 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses