Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-10550.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-10550
Upstream
Published
2022-08-10T20:15:40Z
Modified
2026-04-01T05:06:10.411957Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
CVE-2022-30629 affecting package golang for versions less than 1.18.5-1
Details

Non-random values for ticketageadd in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

References

Affected packages

Azure Linux:2 / golang

Package

Name
golang
Purl
pkg:rpm/azure-linux/golang

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.18.0
Fixed
1.18.5-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-10550.json"