CVE-2021-22917: Infoleak
Published Jul 12, 2021
·Updated
Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowing through Tor if adblocking was enabled.
Affected Software
1 affected component
Brave Browser>1.17<1.20
Event History
Jul 12, 2021
CVE Published
via MITRE·10:22 AM
Data Sourced
via MITRE·10:22 AM
DescriptionWeakness
Frequently Asked Questions
1
What is vulnerable to information disclosure in Brave Browser Desktop versions 1.17 to 1.20?
DNS requests in Tor windows not flowing through Tor if adblocking was enabled.
2
What is the severity level of CVE-2021-22917?
Medium severity with a CVSS score of 6.5.
3
How can I fix the information disclosure vulnerability in Brave Browser Desktop versions 1.17 to 1.20?
Upgrade to a version higher than 1.20 or apply the necessary patches provided by Brave Browser.
4
Is adblocking responsible for the information disclosure vulnerability in Brave Browser Desktop versions 1.17 to 1.20?
Yes, if adblocking is enabled, DNS requests in Tor windows may not flow through Tor, leading to information disclosure.
5
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2021-22917?
CWE-200.