CVE-2021-22916

In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking feature issues DNS requests that used the system DNS settings instead of the extension's proxy settings, resulting in possible information disclosure.
References
Link Resource
https://hackerone.com/reports/1203842 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:brave:brave:*:*:*:*:*:*:*:*

History

30 Aug 2022, 22:38

Type Values Removed Values Added
CWE CWE-200 NVD-CWE-Other

13 Jul 2021, 19:33

Type Values Removed Values Added
References (MISC) https://hackerone.com/reports/1203842 - (MISC) https://hackerone.com/reports/1203842 - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 5.9
CPE cpe:2.3:a:brave:brave:*:*:*:*:*:*:*:*
CWE CWE-200

12 Jul 2021, 11:45

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-12 11:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-22916

Mitre link : CVE-2021-22916

CVE.ORG link : CVE-2021-22916


JSON object : View

Products Affected

brave

  • brave
CWE
NVD-CWE-Other CWE-200

Exposure of Sensitive Information to an Unauthorized Actor