CVE-2024-49025
published 2024-11-14CVE-2024-49025: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
PriorityP416medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.50%
40.1th percentile
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_chromium | < 131.0.2903.48 | 131.0.2903.48 |
| microsoft | microsoft_edge | >= 1.0.0 < 131.0.2903.48 | 131.0.2903.48 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
vendor_msrc5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
vendor_msrc·2024-11-12·CVSS 5.4
CVE-2024-49025 [MEDIUM] CWE-359 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is Personally Identifiable Information (PII).
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L)? What does that mean for this vulnerability?
Information in the victim's browser associated with the vulnerable URL can be read by the malicious JavaScript code and sent to the attacker.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
Exploitation of the vulnerability requires that a user open a specially
GHSA
GHSA-ffvh-7vg3-xhxh: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
ghsa_unreviewed·2024-11-14
CVE-2024-49025 [MEDIUM] CWE-359 GHSA-ffvh-7vg3-xhxh: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-14
Published