« Volver al listado

CVE-2022-24073

Estado: ModificadaAlta (7.1)—

The Web Request API in Whale browser before 3.12.129.18 allowed to deny access to the extension store or redirect to any URL when users access the store.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-24073",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@navercorp.com",
      "affectedData": [
        {
          "vendor": "NAVER",
          "product": "NAVER Whale browser",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "3.12.129.46",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-03-17T06:15:06.827",
  "references": [
    {
      "url": "https://cve.naver.com/detail/cve-2022-24073",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@navercorp.com"
    },
    {
      "url": "https://cve.naver.com/detail/cve-2022-24073",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@navercorp.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-648"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Web Request API in Whale browser before 3.12.129.18 allowed to deny access to the extension store or redirect to any URL when users access the store."
    },
    {
      "lang": "es",
      "value": "La API de peticiones Web en Whale browser versiones anteriores a 3.12.129.18 permitía denegar el acceso a la tienda de extensiones o redirigir a cualquier URL cuando los usuarios accedían a la tienda"
    }
  ],
  "lastModified": "2026-06-17T04:31:15.387",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:navercorp:whale:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47138F1B-655D-4459-905C-7BFA3A326DC5",
              "versionEndExcluding": "3.12.129.18"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@navercorp.com"
}