CVE-2020-8918: Improper Initialization
(updated )
An improperly initialized migrationAuth' value in Google's go-tpm library can lead an eavesdropping attacker to discover the
authvalue for a key created with CreateWrapKey. An attacker listening in on the channel can collect both
encUsageAuthand
encMigrationAuth, and then can calculate
usageAuth ^ encMigrationAuthas the
migrationAuthcan be guessed for all keys created with
CreateWrapKey`.
References
Detect and mitigate CVE-2020-8918 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →