CVE-2022-47934: Medium severity brave browser vulnerability
Published Dec 24, 2022
·Updated
Brave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a crafted HTML file that mentions an ipfs:// or ipns:// URL. This is caused by an incomplete fix for CVE-2022-47932 and CVE-2022-47934.
Affected Software
1 affected component
Brave Brave<1.43.88
Remediation
Patch Available
Event History
Dec 24, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-47934.
2
What is the severity of CVE-2022-47934?
The severity of CVE-2022-47934 is medium with a CVSS score of 6.5.
3
Which software versions are affected by CVE-2022-47934?
Brave Browser versions up to and excluding 1.43.88 are affected by CVE-2022-47934.
4
How can a remote attacker exploit CVE-2022-47934?
A remote attacker can cause a denial of service in private and guest windows by using a crafted HTML file that mentions an ipfs:// or ipns:// URL.
5
Is there a fix available for CVE-2022-47934?
Yes, a fix for CVE-2022-47934 is available in Brave Browser version 1.43.88 and later.