Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
History

Fri, 06 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Jun 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat stf
CPEs cpe:/a:redhat:service_telemetry_framework:1.5::el8 cpe:/a:redhat:stf:1.5::el8
Vendors & Products Redhat service Telemetry Framework
Redhat stf

Sun, 08 Sep 2024 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat multicluster Engine
CPEs cpe:/a:redhat:acm:2.4::el8
cpe:/a:redhat:acm:2.5::el8
cpe:/a:redhat:acm:2.6::el8
cpe:/a:redhat:multicluster_engine:2.1::el8
Vendors & Products Redhat multicluster Engine

Mon, 19 Aug 2024 22:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.4::el8
cpe:/a:redhat:acm:2.5::el8
cpe:/a:redhat:acm:2.6::el8
cpe:/a:redhat:multicluster_engine:2.1::el8
Vendors & Products Redhat multicluster Engine

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published: 2022-08-09T20:17:31.000Z

Updated: 2026-03-06T19:12:16.725Z

Reserved: 2022-05-12T00:00:00.000Z

Link: CVE-2022-30629

cve-icon Vulnrichment

Updated: 2024-08-03T06:56:13.230Z

cve-icon NVD

Status : Modified

Published: 2022-08-10T20:15:40.560

Modified: 2026-03-06T20:16:10.730

Link: CVE-2022-30629

cve-icon Redhat

Severity : Low

Publid Date: 2022-06-02T00:00:00Z

Links: CVE-2022-30629 - Bugzilla