Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2hh3-2vjw-vgr4

Опубликовано: 18 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.

Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.

EPSS

Процентиль: 66%
0.00504
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-668
CWE-732

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.

EPSS

Процентиль: 66%
0.00504
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-668
CWE-732