GO-2021-0095

    Dashboard / Vulnerabilities / GO-2021-0095

    GO-2021-0095

    Published: 14 Apr 2021Last Modified: 20 May 2024

    Summary: Sensitive information exposure in github.com/google/go-tpm

    Details: Due to repeated usage of a XOR key an attacker that can eavesdrop on the TPM 1.2 transport is able to calculate usageAuth for keys created using CreateWrapKey, despite it being encrypted, allowing them to use the created key.

    Affected packages

    Package

    Name: github.com/google/go-tpm

    Purl: pkg:golang/github.com/google/go-tpm

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.3.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GO-2021-0095 | CVE-DB