Tang Project Tang vulnerabilities
2 known vulnerabilities affecting tang_project/tang.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-1672MEDIUMCVSS 5.3fixed in 142023-07-11
CVE-2023-1672 [MEDIUM] CWE-362 CVE-2023-1672: A race condition exists in the Tang server functionality for key generation and key rotation. This f
A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.
nvdosv
CVE-2021-4076HIGHCVSS 7.5≥ 8, < 11vAffects tang v8 and above | Fixed in tang v11.2022-03-02
CVE-2021-4076 [HIGH] CWE-200 CVE-2021-4076: A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of p
A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.
cvelistv5nvdosv