PT-2023-6851 · Brave · Brave Browser
Kalki
·
Publicado
2023-02-09
·
Atualizado
2023-02-17
·
CVE-2023-22798
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Brave Browser versions prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0
Description
The issue is related to the removal of redirect interceptors on certain websites, such as Facebook, which could have been in place for security purposes. This removal, known as "debouncing", may cause open redirects on these websites, potentially allowing a remote attacker to redirect users to an arbitrary URL. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations
For versions prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, consider updating to a version that includes the commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0 to resolve the issue. As a temporary workaround, users may want to exercise caution when clicking on links from websites that may have had redirect interceptors removed, such as Facebook.
Exploit
Correção
Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Brave Browser