Aggregates CVE and security vulnerability intelligence across all briarproject-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Common weakness patterns include vendor risk denial of service, with potential vendor impact application crash across vendor surface software deployment and vendor surface production workloads use cases.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-33983 | The Introduction Client in Briar through 1.5.3 does not implement out-of-band verification for the public keys of introducees. An introducer can launch man-in-the-middle attacks against later private communication between two introduced parties. | [email protected] | 7.4 | 0.34% | 2023-05-24 | 2025-01-16 |
| CVE-2023-33982 | Bramble Handshake Protocol (BHP) in Briar before 1.5.3 is not forward secure: eavesdroppers can decrypt network traffic between two accounts if they later compromise both accounts. NOTE: the eavesdropping is typically impractical because BHP runs over an encrypted session that uses the Tor hidden service protocol. | [email protected] | 5.9 | 0.19% | 2023-05-24 | 2025-01-16 |
| CVE-2023-33981 | Briar before 1.4.22 allows attackers to spoof other users' messages in a blog, forum, or private group, but each spoofed message would need to be an exact duplicate of a legitimate message displayed alongside the spoofed one. | [email protected] | 6.5 | 0.12% | 2023-05-24 | 2025-01-16 |
| CVE-2023-33980 | Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a series of long messages to a contact. | [email protected] | 7.5 | 0.54% | 2023-05-24 | 2025-01-16 |