First published: Tue Aug 31 2021(Updated: )
An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor.log.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Brave Browser | <1.28.62 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22929 is an information disclosure vulnerability in Brave Browser Desktop prior to version 1.28.62.
CVE-2021-22929 has a severity rating of 6.1 (medium).
CVE-2021-22929 allows logged warning messages that include timestamps of connections to V2 onion domains in tor.log to be disclosed.
To fix CVE-2021-22929, update your Brave Browser Desktop to version 1.28.62 or newer.
You can find more information about CVE-2021-22929 at the following link: [Link to HackerOne report](https://hackerone.com/reports/1249056)