Описание
WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| qbittorrent | fixed | 3.3.7-3 | package | |
| qbittorrent | no-dsa | jessie | package |
Примечания
https://github.com/qbittorrent/qBittorrent/commit/f5ad04766f4abaa78374ff03704316f8ce04627d
Fixed upstream in 3.3.11
EPSS
Процентиль: 47%
0.00238
Низкий
Связанные уязвимости
CVSS3: 6.1
ubuntu
почти 9 лет назад
WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.
CVSS3: 6.1
nvd
почти 9 лет назад
WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.
CVSS3: 6.1
github
больше 3 лет назад
WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.
EPSS
Процентиль: 47%
0.00238
Низкий