CVE-2022-30629
Summary
| CVE | CVE-2022-30629 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-10 20:15:00 UTC |
| Updated | 2023-11-07 03:47:00 UTC |
| Description | Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| crypto/tls: randomly generate ticket_age_add [freeze exception] · Issue #52814 · golang/go · GitHub |
MISC |
go.dev |
|
| July 2022 Golang Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| fe4de36198794c447fbd9d7cc2d7199a506c76a5 - go - Git at Google |
MISC |
go.googlesource.com |
|
| [security] Go 1.18.3 and Go 1.17.11 are released |
MISC |
groups.google.com |
|
| GO-2022-0531 - Go Packages |
MISC |
pkg.go.dev |
|
| [SECURITY] Fedora 35 Update: fzf-0.29.0-2.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| go.dev/cl/405994 |
MISC |
go.dev |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159981 Oracle Enterprise Linux Security Update for go-toolset:ol8addon (ELSA-2022-17956)
- 160591 Oracle Enterprise Linux Security Update for podman (ELSA-2023-2282)
- 160595 Oracle Enterprise Linux Security Update for skopeo (ELSA-2023-2283)
- 160596 Oracle Enterprise Linux Security Update for buildah (ELSA-2023-2253)
- 160600 Oracle Enterprise Linux Security Update for containernetworking-plugins (ELSA-2023-2367)
- 160678 Oracle Enterprise Linux Security Update for container-tools:ol8 (ELSA-2023-2758)
- 199304 Ubuntu Security Notification for Go Vulnerabilities (USN-6038-1)
- 240617 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2022:6102)
- 240684 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2022:6535)
- 241268 Red Hat Update for multiple OpenStack Platforms (RHSA-2023:1275)
- 241428 Red Hat Update for podman (RHSA-2023:2282)
- 241460 Red Hat Update for containernetworking-plugins (RHSA-2023:2367)
- 241465 Red Hat Update for skopeo (RHSA-2023:2283)
- 241470 Red Hat Update for buildah (RHSA-2023:2253)
- 241505 Red Hat Update for container-tools:rhel8 security (RHSA-2023:2758)
- 241776 Red Hat Update for red hat openshift enterprise (RHSA-2023:3914)
- 282893 Fedora Security Update for 3mux (FEDORA-2022-fae3ecee19)
- 282931 Fedora Security Update for apptainer (FEDORA-2022-ba365d3703)
- 283049 Fedora Security Update for fzf (FEDORA-2022-30c5ed5625)
- 284299 Fedora Security Update for etcd (FEDORA-2022-28d38313c8)
- 354064 Amazon Linux Security Advisory for golist : ALAS2-2022-1847
- 354067 Amazon Linux Security Advisory for golang : ALAS2-2022-1846
- 354069 Amazon Linux Security Advisory for golang : ALAS-2022-1635
- 354083 Amazon Linux Security Advisory for runc : ALAS2DOCKER-2022-020
- 354088 Amazon Linux Security Advisory for golang-github-syndtr-gocapability : ALAS2-2022-1865
- 354089 Amazon Linux Security Advisory for golang-googlecode-sqlite : ALAS2-2022-1862
- 354090 Amazon Linux Security Advisory for golang-github-kr-pty : ALAS2-2022-1864
- 354091 Amazon Linux Security Advisory for go-rpm-macros : ALAS2-2022-1863
- 354092 Amazon Linux Security Advisory for golang-googlecode-net : ALAS2-2022-1861
- 354093 Amazon Linux Security Advisory for golang-github-gorilla-mux : ALAS2-2022-1860
- 354094 Amazon Linux Security Advisory for golang-github-gorilla-context : ALAS2-2022-1859
- 354096 Amazon Linux Security Advisory for golang-github-godbus-dbus : ALAS2-2022-1858
- 354370 Amazon Linux Security Advisory for golang-github-cpuguy83-md2man : ALAS2022-2022-140
- 354493 Amazon Linux Security Advisory for golist : ALAS2022-2022-133
- 354504 Amazon Linux Security Advisory for golist : ALAS2022-2022-192
- 354527 Amazon Linux Security Advisory for golang : ALAS2022-2022-193
- 354566 Amazon Linux Security Advisory for golang : ALAS-2022-193
- 355111 Amazon Linux Security Advisory for golist : ALAS2023-2023-046
- 355186 Amazon Linux Security Advisory for golang-github-cpuguy83-md2man : ALAS2023-2023-047
- 355212 Amazon Linux Security Advisory for golang : ALAS2023-2023-048
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 502459 Alpine Linux Security Update for go
- 672085 EulerOS Security Update for golang (EulerOS-SA-2022-2317)
- 672112 EulerOS Security Update for golang (EulerOS-SA-2022-2288)
- 672174 EulerOS Security Update for golang (EulerOS-SA-2022-2439)
- 672294 EulerOS Security Update for golang (EulerOS-SA-2022-2651)
- 672302 EulerOS Security Update for golang (EulerOS-SA-2022-2683)
- 690876 Free Berkeley Software Distribution (FreeBSD) Security Update for go (15888c7e-e659-11ec-b7fe-10c37b4ac2ea)
- 710584 Gentoo Linux Go Multiple Vulnerabilities (GLSA 202208-02)
- 753266 SUSE Enterprise Linux Security Update for go1.18 (SUSE-SU-2022:2005-1)
- 753436 SUSE Enterprise Linux Security Update for go1.17 (SUSE-SU-2022:2004-1)
- 754047 SUSE Enterprise Linux Security Update for go1.18-openssl (SUSE-SU-2023:2312-1)
- 770163 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2022:6102)
- 770164 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2022:6535)
- 770204 Red Hat OpenShift Container Platform 4.11 Security Update (RHSA-2023:3914)
- 902746 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10550)
- 902749 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10562)
- 903968 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10550-1)
- 903980 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10562-1)
- 907763 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10562-2)
- 907864 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (10550-2)
- 941034 AlmaLinux Security Update for podman (ALSA-2023:2282)
- 941035 AlmaLinux Security Update for buildah (ALSA-2023:2253)
- 941052 AlmaLinux Security Update for containernetworking-plugins (ALSA-2023:2367)
- 941055 AlmaLinux Security Update for skopeo (ALSA-2023:2283)
- 941116 AlmaLinux Security Update for container-tools:rhel8 (ALSA-2023:2758)
- 960463 Rocky Linux Security Update for go-toolset:rhel8 (RLSA-2022:5775)
- 960612 Rocky Linux Security Update for go-toolset and golang (RLSA-2022:5799)