← Back to CVE List

CVE-2017-7822

Published: 2018-06-11T21:29Z
Last Modified: 2024-11-21T03:32Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The AES-GCM implementation in WebCrypto API accepts 0-length IV when it should require a length of 1 according to the NIST Special Publication 800-38D specification. This might allow for the authentication key to be determined in some instances. This vulnerability affects Firefox < 56. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt