PT-2023-6851 · Brave · Brave Browser

Kalki

·

Publicado

2023-02-09

·

Atualizado

2023-02-17

·

CVE-2023-22798

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Brave Browser versions prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0
Description The issue is related to the removal of redirect interceptors on certain websites, such as Facebook, which could have been in place for security purposes. This removal, known as "debouncing", may cause open redirects on these websites, potentially allowing a remote attacker to redirect users to an arbitrary URL. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For versions prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, consider updating to a version that includes the commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0 to resolve the issue. As a temporary workaround, users may want to exercise caution when clicking on links from websites that may have had redirect interceptors removed, such as Facebook.

Exploit

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07860
CVE-2023-22798

Produtos afetados

Brave Browser