CVE-2022-24074

Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:navercorp:whale:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:49

Type Values Removed Values Added
References () https://cve.naver.com/detail/cve-2022-24074 - Vendor Advisory () https://cve.naver.com/detail/cve-2022-24074 - Vendor Advisory

30 Jun 2023, 18:50

Type Values Removed Values Added
CWE CWE-732 CWE-668

Information

Published : 2022-03-17 06:15

Updated : 2024-11-21 06:49


NVD link : CVE-2022-24074

Mitre link : CVE-2022-24074

CVE.ORG link : CVE-2022-24074


JSON object : View

Products Affected

navercorp

  • whale
CWE
CWE-668

Exposure of Resource to Wrong Sphere