Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-45287

23
FAUCET Score

CVE-2023-45287 is a high-severity timing side-channel vulnerability affecting Go versions prior to 1.20, specifically within the crypto/tls library's RSA key exchange implementation. The flaw, rated 7.5 CVSS, could allow an unauthenticated attacker to remotely recover session key bits by exploiting timing information leaked during PKCS#1 padding removal. While RSA blinding was intended to mitigate such attacks, it was found to be insufficient. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.20.0CPE matchmatch criteria
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.25%
Probability of exploitation in next 30 days
EPSS Percentile
66.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0125 is in the 46th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (85)

microsoftpatch availablevia msrc
Product: 18157-16823Fixed in: 1.20.0-1
microsoftpatch availablevia msrc
Product: 18156-16823Fixed in: 1.20.0-1
microsoftpatch availablevia msrc
Product: azl3 golang 1.20.0-1 on Azure Linux 3.0Fixed in: 1.20.0-1
microsoftpatch availablevia msrc
Product: cbl2 golang 1.17.13-2 on CBL Mariner 2.0
microsoftpatch availablevia msrc
Product: 17375-16823Fixed in: 1.21.6-1
microsoftpatch availablevia msrc
Product: 19785-17086
microsoftpatch availablevia msrc
Product: 19778-17086
microsoftpatch availablevia msrc
Product: cbl2 golang 1.18.8-7 on CBL Mariner 2.0
microsoftpatch availablevia msrc
Product: cbl2 golang 1.21.6-1 on CBL Mariner 2.0Fixed in: 1.21.6-1
microsoftpatch availablevia msrc
Product: 18158-17084Fixed in: 1.20.0-1
microsoftpatch availablevia msrc
Product: cbl2 msft-golang 1.20.0-1 on CBL Mariner 2.0Fixed in: 1.20.0-1
microsoftpatch availablevia msrc
Product: cbl2 golang 1.20.0-1 on CBL Mariner 2.0Fixed in: 1.20.0-1
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: butane-0:0.20.0-1.rhaos4.15.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: containernetworking-plugins-1:1.4.0-1.1.rhaos4.15.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: openshift-0:4.15.0-202402142009.p0.g6216ea1.assembly.stream.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: openshift-clients-0:4.15.0-202402070507.p0.g48dcf59.assembly.stream.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: podman-3:4.4.1-21.rhaos4.15.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: runc-4:1.1.12-1.rhaos4.15.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: skopeo-2:1.11.2-21.1.rhaos4.15.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: microshift-0:4.15.0-202402260721.p0.g799289b.assembly.4.15.0.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 17.1 for RHEL 8Fixed in: collectd-sensubility-0:0.2.1-3.el8ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 17.1 for RHEL 9Fixed in: etcd-0:3.4.26-8.el9ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 17.1 for RHEL 9Fixed in: collectd-sensubility-0:0.2.1-3.el9ost
View patch
redhatpatch availablevia redhat_api
Product: RODOO-1.1-RHEL-9Fixed in: run-once-duration-override-operator/run-once-duration-override-operator-bundle:v1.1-4
View patch
redhatpatch availablevia redhat_api
Product: RODOO-1.1-RHEL-9Fixed in: run-once-duration-override-operator/run-once-duration-override-rhel9:v1.1-4
View patch
redhatpatch availablevia redhat_api
Product: RODOO-1.1-RHEL-9Fixed in: run-once-duration-override-operator/run-once-duration-override-rhel9-operator:v1.1-5
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-config-sync-rhel9:1.5.3-1
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-controller-podman-rhel9:1.5.3-1
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-flow-collector-rhel9:1.5.3-2
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-operator-bundle:1.5.3-3
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-router-rhel9:2.5.1-2
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-service-controller-rhel9:1.5.3-1
View patch
redhatpatch availablevia redhat_api
Product: Service Interconnect 1 for RHEL 9Fixed in: service-interconnect/skupper-site-controller-rhel9:1.5.3-2
View patch
redhatpatch availablevia redhat_api
Product: STF-1.5-RHEL-8Fixed in: stf/sg-core-rhel8:5.2.1-6
View patch
redhatpatch availablevia redhat_api
Product: MTA-7.0-RHEL-9Fixed in: mta/mta-cli-rhel9:7.0.3-16
View patch
redhatpatch availablevia redhat_api
Product: OSSO-1.2-RHEL-9Fixed in: openshift-secondary-scheduler-operator/secondary-scheduler-operator-bundle:v1.2-19
View patch
redhatpatch availablevia redhat_api
Product: OSSO-1.2-RHEL-9Fixed in: openshift-secondary-scheduler-operator/secondary-scheduler-rhel9-operator:v1.2-26
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:4.0-8090020240201111813.d7b6f4b7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:rhel8-8100020240227110532.82888897
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: runc-4:1.1.12-2.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: podman-2:4.9.4-0.1.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: skopeo-2:1.14.3-0.1.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: buildah-2:1.33.6-2.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: containernetworking-plugins-1:1.4.0-2.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: containernetworking-plugins-1:1.2.0-3.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: buildah-1:1.29.1-20.2.rhaos4.15.el9
View patch
redhatpatch availablevia redhat_api
Product: OADP-1.3-RHEL-9Fixed in: oadp/oadp-velero-rhel9:1.3.1-16
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Certification Program for Red Hat Enterprise Linux 9Fixed in: redhat-certification-preflight
redhatvendor investigatingvia redhat_api
Product: Red Hat Certification for Red Hat Enterprise Linux 8Fixed in: redhat-certification-preflight
redhatvendor investigatingvia redhat_api
Product: Red Hat Web TerminalFixed in: web-terminal-exec-container
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/subctl-rhel8
redhatno patchvia redhat_api
Product: Cryostat 2Fixed in: cryostat-tech-preview/cryostat-rhel8-operator
redhatno patchvia redhat_api
Product: Logical Volume Manager StorageFixed in: lvms4/topolvm-rhel9
redhatno patchvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: migration-toolkit-virtualization/mtv-api-rhel9
redhatno patchvia redhat_api
Product: mirror registry for Red Hat OpenShiftFixed in: mirror-registry-container
redhatno patchvia redhat_api
Product: OpenShift Developer Tools and ServicesFixed in: helm
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines-client
redhatno patchvia redhat_api
Product: Power monitoring for Red Hat OpenShiftFixed in: kepler-container
redhatno patchvia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-operator-container
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Security 3Fixed in: advanced-cluster-security/rhacs-main-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Security 4Fixed in: advanced-cluster-security/rhacs-main-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: aap-cloud-ui-container
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 5Fixed in: rhceph/rhceph-5-dashboard-rhel8
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: go-toolset:rhel8/go-toolset
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: ignition
redhatno patchvia redhat_api
Product: Red Hat OpenShift on AWSFixed in: rosa
redhatno patchvia redhat_api
Product: Red Hat Openshift Sandboxed ContainersFixed in: openshift-sandboxed-containers/osc-rhel9-operator
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: etcd
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 17.1Fixed in: golang-github-infrawatch-apputils
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 18.0Fixed in: rhoso-operators/ovn-rhel9-operator
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/clair-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: golang-github-infrawatch-apputils
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: rhosp-rhel8/osp-director-agent
redhatend of lifevia redhat_api
Product: OpenShift Developer Tools and ServicesFixed in: ocp-tools-4/jenkins-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 18.0Fixed in: etcd
redhatend of lifevia redhat_api
Product: NBDE Tang ServerFixed in: tang-operator-container
redhatend of lifevia redhat_api
Product: Migration Toolkit for Applications 6Fixed in: mta/mta-hub-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Storage 3Fixed in: golang
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: grafana-pcp
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: grafana
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: osbuild-composer
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Data Science (RHODS)Fixed in: rhods/odh-mm-rest-proxy-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: osbuild-composer
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: grafana-pcp
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: grafana

Vendor Advisories (2)

microsoft2023-Dec/CVE-2023-45287

Before Go 1.20, the RSA based key exchange methods in crypto/tls may exhibit a timing side channel

Dec 12, 2023
redhatCVE-2023-45287Moderate

golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges.

Dec 5, 2023

References

go.dev / cl/326012/26
Issue Tracking
go.dev / issue/20654
Issue Tracking
groups.google.com / g/golang-announce/c/QMK8IQALDvA
Mailing ListRelease Notes
people.redhat.com / ~hkario/marvin
Third Party Advisory
pkg.go.dev / vuln/GO-2023-2375
Vendor Advisory
security.netapp.com / advisory/ntap-20240112-0005