CVE-2021-22916

In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking feature issues DNS requests that used the system DNS settings instead of the extension's proxy settings, resulting in possible information disclosure.
References
Link Resource
https://hackerone.com/reports/1203842 Third Party Advisory
https://hackerone.com/reports/1203842 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:brave:brave:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:50

Type Values Removed Values Added
References () https://hackerone.com/reports/1203842 - Third Party Advisory () https://hackerone.com/reports/1203842 - Third Party Advisory

Information

Published : 2021-07-12 11:15

Updated : 2024-11-21 05:50


NVD link : CVE-2021-22916

Mitre link : CVE-2021-22916

CVE.ORG link : CVE-2021-22916


JSON object : View

Products Affected

brave

  • brave
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-Other