CVE Vulnerabilities

CVE-2021-22916

Published: Jul 12, 2021 | Modified: Aug 30, 2022
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking feature issues DNS requests that used the system DNS settings instead of the extensions proxy settings, resulting in possible information disclosure.

Affected Software

Name Vendor Start Version End Version
Brave Brave 1.17.0 (including) 1.26.60 (including)

References