CVE-2022-47933: Medium severity brave browser vulnerability
Published Dec 24, 2022
·Updated
Brave Browser before 1.42.51 allowed a remote attacker to cause a denial of service via a crafted HTML file that references the IPFS scheme. This vulnerability is caused by an uncaught exception in the function ipfs::OnBeforeURLRequestIPFSRedirectWork() in ipfsredirectnetworkdelegatehelper.cc.
Affected Software
1 affected component
Brave Brave<1.42.51
Remediation
Patch Available
Event History
Dec 24, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-47933.
2
What is the severity of CVE-2022-47933?
The severity of CVE-2022-47933 is medium with a CVSS score of 6.5.
3
What is the affected software?
The affected software is Brave Browser before version 1.42.51.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by crafting an HTML file that references the IPFS scheme.
5
Is there a fix available for CVE-2022-47933?
Yes, a fix for CVE-2022-47933 is available in Brave Browser version 1.42.51.