CVE-2021-45884: Infoleak
In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled, additional DNS requests are issued outside of the proxying extension using the system's DNS settings, resulting in information disclosure. NOTE: this issue exists because of an incomplete fix for CVE-2021-21323 and CVE-2021-22916.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-45884?
CVE-2021-45884 is a vulnerability in Brave Desktop versions 1.17 through 1.33 before 1.33.106 that allows DNS requests to be issued outside of a proxying extension, leading to information disclosure.
What is the severity of CVE-2021-45884?
The severity of CVE-2021-45884 is high with a severity value of 7.5.
How does CVE-2021-45884 affect Brave Desktop?
CVE-2021-45884 affects Brave Desktop versions 1.17 through 1.33 before 1.33.106 when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled.
How can I fix CVE-2021-45884?
To fix CVE-2021-45884, update Brave Desktop to version 1.33.106 or later.
Are there any references for CVE-2021-45884?
Yes, you can find references for CVE-2021-45884 in the following links: [GitHub Issue 19070](https://github.com/brave/brave-browser/issues/19070), [GitHub Issue 20079](https://github.com/brave/brave-browser/issues/20079), [GitHub Pull Request 10742](https://github.com/brave/brave-core/pull/10742).