CVE-2017-1000461
Last modified
CVE-2017-1000461 is a vulnerability of currently unknown severity. Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the "JS fingerprinting blocking" component, resulting in a malicious website being able to access the fingerprinting-associated browser functionality (that the browser intends to block).. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the "JS fingerprinting blocking" component, resulting in a malicious website being able to access the fingerprinting-associated browser functionality (that the browser intends to block).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Brave | Browser | <= 0.19.73 |
References
- https://github.com/brave/browser-laptop/issues/11683#issuecomment-339835601Third Party Advisory
- https://github.com/brave/browser-laptop/issues/11683#issuecomment-339835601Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-1000461?
How severe is CVE-2017-1000461?
How do I fix CVE-2017-1000461?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-1000455GuixSD prior to Git commit 5e66574a128937e7f2fcf146d14622570…
- CVE-2017-1000456freedesktop.org libpoppler 0.60.1 fails to validate boundari…
- CVE-2017-1000457Cross-site scripting (XSS) vulnerability in Help.aspx in moj…
- CVE-2017-1000458Bro before Bro v2.5.2 is vulnerable to an out of bounds writ…
- CVE-2017-1000459Leanote version <= 2.5 is vulnerable to XSS due to not sanit…
- CVE-2017-1000460In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(…
- CVE-2017-1000462BookStack version 0.18.4 is vulnerable to stored cross-site …
- CVE-2017-1000463Leafpub version 1.2.0-beta6 is vulnerable to stored cross-si…
- CVE-2017-1000464Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-1000465Sulu-standard version 1.6.6 is vulnerable to stored cross-si…
- CVE-2017-1000466Invoice Ninja version 3.8.1 is vulnerable to stored cross-si…
- CVE-2017-1000467LavaLite version 5.2.4 is vulnerable to stored cross-site sc…
Are you affected by CVE-2017-1000461?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
