PT-2021-14420 · Brave · Brave
Newfunction
·
Published
2021-02-23
·
Updated
2022-01-07
·
CVE-2021-21323
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Brave versions 1.17.73 through 1.20.103
Description
The issue concerns the CNAME adblocking feature in Brave, which was added in version 1.17.73. This feature accidentally initiated DNS requests that bypassed the Brave Tor proxy. As a result, users with adblocking enabled would leak DNS requests from Tor windows to their DNS provider. DNS requests not initiated by CNAME adblocking would still go through Tor as expected.
Recommendations
For versions 1.17.73 through 1.20.103, update to version 1.20.108 to resolve the issue.
As a temporary workaround, consider disabling the CNAME adblocking feature until the update to version 1.20.108 is applied.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brave