PT-2021-15274 · Brave · Brave Browser

Newfunction

·

Published

2021-07-12

·

Updated

2022-08-30

·

CVE-2021-22917

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Brave Browser Desktop versions 1.17 through 1.20
Description The issue concerns information disclosure through DNS requests in Tor windows that do not flow through Tor when adblocking is enabled.
Recommendations For versions 1.17 through 1.20, consider disabling adblocking in Tor windows as a temporary workaround until a patch is available. Restrict the use of Tor windows with adblocking enabled to minimize the risk of information disclosure.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2021-22917

Affected Products

Brave Browser