CVE-2017-8458: Medium severity brave browser vulnerability
Published May 3, 2017
·Updated
Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://safe.example.com@unsafe.example.com/ is displayed without a clear UI indication that it is not a resource on the safe.example.com web site.
Affected Software
1 affected component
Brave Brave=0.12.4
Remediation
Patch Available
Event History
May 3, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8458?
The severity of CVE-2017-8458 is considered moderate due to the potential for phishing attacks.
2
How do I fix CVE-2017-8458?
To fix CVE-2017-8458, users should upgrade to a version of Brave newer than 0.12.4 that addresses the URI obfuscation issue.
3
What type of vulnerability is CVE-2017-8458?
CVE-2017-8458 is classified as a URI obfuscation vulnerability.
4
Which version of Brave is affected by CVE-2017-8458?
Brave version 0.12.4 is the affected version for CVE-2017-8458.
5
What could happen if I don't address CVE-2017-8458?
If CVE-2017-8458 is not addressed, users may be susceptible to phishing scams due to misleading URL displays.