CVE-2021-22929

Published Aug 31, 2021

Last updated 3 years ago

Overview

Description
An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor.log.
Source
support@hackerone.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
6.1
Impact score
4.2
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
3.6
Impact score
4.9
Exploitability score
3.9
Vector string
AV:L/AC:L/Au:N/C:P/I:P/A:N

Weaknesses

nvd@nist.gov
CWE-532
support@hackerone.com
CWE-312

Social media

Hype score
Not currently trending

Configurations