CVE-2023-52263

Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_client.cc and browser/ui/webui/brave_web_ui_controller_factory.cc.
Configurations

Configuration 1 (hide)

cpe:2.3:a:brave:browser:*:*:*:*:*:*:*:*

History

09 Jan 2024, 21:37

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:brave:browser:*:*:*:*:*:*:*:*
References () https://github.com/brave/brave-browser/issues/32449 - () https://github.com/brave/brave-browser/issues/32449 - Issue Tracking, Patch
References () https://github.com/brave/brave-browser/issues/32473 - () https://github.com/brave/brave-browser/issues/32473 - Issue Tracking, Patch
References () https://github.com/brave/brave-core/pull/19820 - () https://github.com/brave/brave-core/pull/19820 - Issue Tracking, Patch
References () https://github.com/brave/brave-core/pull/19820/commits/9da202f7f4bc80b6975909b684bbc0764a31c4e9 - () https://github.com/brave/brave-core/pull/19820/commits/9da202f7f4bc80b6975909b684bbc0764a31c4e9 - Patch
First Time Brave browser
Brave
Summary
  • (es) Brave Browser anterior a 1.59.40 no restringe adecuadamente el esquema para la fábrica WebUI y la redirección. Esto está relacionado con browser/brave_content_browser_client.cc y browser/ui/webui/brave_web_ui_controller_factory.cc.
CWE CWE-601

30 Dec 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-30 19:15

Updated : 2024-01-09 21:37


NVD link : CVE-2023-52263

Mitre link : CVE-2023-52263

CVE.ORG link : CVE-2023-52263


JSON object : View

Products Affected

brave

  • browser
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')