CVE-2022-30629

SOURCE - nist

Summary

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.

EPSS Score: 0.0014 (0.496)

Common Weakness Enumeration (CWE)

SOURCE - nist

Use of Insufficiently Random Values

SOURCE - redhat

Insufficient Entropy


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in