SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-24075

Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to local HWP files.

MEDIUM 6.5EPSS 0.88%

Does this matter?

Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.

Description

Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to local HWP files. When the HWP files were opened, the replaced script could read the files.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
0.88% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-552
Affected
navercorp/whale
Source
cve@navercorp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.