
CVE-2023-45287 Before Go 1.20, the RSA based key exchange methods in crypto/tls may exhibit a timing side channel http://dlvr.it/TR22WH
Post summary
The text announces a timing side channel vulnerability in Go's RSA TLS key exchange before Go 1.20.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

CVE-2023-45287 Before Go 1.20, the RSA based key exchange methods in crypto/tls may exhibit a timing side channel http://dlvr.it/TR22WH
Post summary
The text announces a timing side channel vulnerability in Go's RSA TLS key exchange before Go 1.20.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | golang | go | - | - | - |