-
Notifications
You must be signed in to change notification settings - Fork 383
Open
Description
Location: usr/local/bin/usql_static
Component Name: stdlib
Component Version: v1.25.5
During the TLS 1.3 handshake if multiple messages are sent in records ...
Target: usr/local/bin/usql_static
Type: gobinary
Fixed version: 1.24.12, 1.25.6
During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels