CVE-2020-15502
Summary
| CVE | CVE-2020-15502 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-02 11:15:00 UTC |
| Updated | 2023-11-07 03:17:00 UTC |
| Description | ** DISPUTED ** The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which might make visit data available temporarily at a Potentially Unwanted Endpoint. NOTE: the vendor has stated "the favicon service adheres to our strict privacy policy." |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Duckduckgo | Duckduckgo | All | All | All | All |
| Application | Duckduckgo | Duckduckgo | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Android/UriExtension.kt at e2f2d54a6b4452277467db403a3546512401b493 · duckduckgo/Android · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Hi all, Founder and CEO of DuckDuckGo here. I’m literally just waking up and rea... | Hacker News | MISC | news.ycombinator.com | Third Party Advisory |
| DuckDuckGo browser seemingly sends domains a user visits to DDG servers | Hacker News | MISC | news.ycombinator.com | Patch, Third Party Advisory |
| Domains visited get leaked to DDG servers · Issue #527 · duckduckgo/Android · GitHub | MISC | github.com | Third Party Advisory |
| iOS/AppUrls.swift at 1ae03d7221180bd6791cf6f7f06922a96335cf75 · duckduckgo/iOS · GitHub | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.