Security Advisory

CVE-2022-30629

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-08-09 20:17:31
Last updated 2026-03-06 19:12:16
Assigner Go
State PUBLISHED

Description

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.