CVE-2021-45884
In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled, additional DNS requests are issued outside of the proxying extension using the system's DNS settings, resulting…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled, additional DNS requests are issued outside of the proxying extension using the system's DNS settings, resulting in information disclosure. NOTE: this issue exists because of an incomplete fix for CVE-2021-21323 and CVE-2021-22916.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 3.09% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- brave/brave
- Source
- cve@mitre.org
References
- https://github.com/brave/brave-browser/issues/19070Exploit, Issue Tracking, Patch, Third Party Advisory
- https://github.com/brave/brave-browser/issues/20079Issue Tracking, Release Notes, Third Party Advisory
- https://github.com/brave/brave-core/pull/10742Patch, Third Party Advisory
- https://hackerone.com/reports/1377864Permissions Required
- https://github.com/brave/brave-browser/issues/19070Exploit, Issue Tracking, Patch, Third Party Advisory
- https://github.com/brave/brave-browser/issues/20079Issue Tracking, Release Notes, Third Party Advisory
- https://github.com/brave/brave-core/pull/10742Patch, Third Party Advisory
- https://hackerone.com/reports/1377864Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.