CVE-2017-15423
—CVSS 3.0
5.3 medium
EPSS
2%p73
Published
()
Modified
Description
Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the low-order bits of SHA512(password) by inspecting protocol traffic.
In the news0 stories
No ingested article mentions this CVE yet.