CVE-2019-5754 is an implementation error in the QUIC networking protocol within Google Chrome versions prior to 72.0.3626.81, also affecting Debian, Fedora, and Red Hat distributions. This medium-severity vulnerability (CVSS 6.5) allows an attacker to obtain cleartext of transport-encrypted data if they can operate or induce the use of a malicious network proxy. While the attack complexity is low and requires user interaction (UI:R), the impact is high confidentiality compromise (C:H). There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, indicating low current threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 72.0.3626.81CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.