Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-32762

Опубликовано: 28 мая 2023
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qt6-basefixed6.4.2+dfsg-9package
qtbase-opensource-srcfixed5.15.8+dfsg-10package
qtbase-opensource-srcfixed5.15.2+dfsg-9+deb11u1bullseyepackage
qtbase-opensource-src-glesnot-affectedpackage

Примечания

  • https://github.com/qt/qtbase/commit/1b736a815be0222f4b24289cf17575fc15707305

EPSS

Процентиль: 31%
0.00116
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 2 лет назад

An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.

CVSS3: 5.3
nvd
больше 2 лет назад

An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.

CVSS3: 5.3
msrc
больше 2 лет назад

An issue was discovered in Qt before 5.15.14 6.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header allowing unencrypted connections to be established even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.

CVSS3: 5.3
github
больше 2 лет назад

An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.

CVSS3: 5.3
fstec
больше 2 лет назад

Уязвимость кроссплатформенного фреймворка для разработки программного обеспечения Qt, связанная с передачей защищаемой информации в незашифрованном виде, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 31%
0.00116
Низкий