Information Disclosure Vulnerability in Brave Browser Desktop
CVE-2021-22917

6.5MEDIUM

Key Information:

Vendor

Brave

Vendor
CVE Published:
12 July 2021

What is CVE-2021-22917?

The Brave Browser Desktop, specifically in versions 1.17 to 1.20, is susceptible to an information disclosure vulnerability. When users activate adblocking while using Tor, DNS requests may not be correctly routed through the Tor network. This flaw could potentially allow malicious entities to glean sensitive information through unprotected DNS queries, raising concerns about user privacy and system security.

Affected Version(s)

https://github.com/brave/brave-core Fixed in 1.20

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.