CVE-2017-8458
MEDIUMBrave - Injection
Title source: ruleDescription
Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://[email protected]/ is displayed without a clear UI indication that it is not a resource on the safe.example.com web site.
Scores
CVSS v3
6.5
EPSS
0.0045
EPSS Percentile
63.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Classification
CWE
CWE-74
Status
published
Affected Products (2)
brave/brave
n/a/n/a
Timeline
Published
May 03, 2017
Tracked Since
Feb 18, 2026