CVE-2022-24072
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/03/2022
Last modified:
23/03/2022
Description
The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page via devtools.inspectedWindow, leading to extensions downloading and uploading when users open the developer tool.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:navercorp:whale:*:*:*:*:*:*:*:* | 3.12.129.18 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



