Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-39936

Опубликовано: 04 июл. 2024
Источник: redhat
CVSS3: 7.5

Описание

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

A vulnerability was found in Qt where, during a TLS connection for servers supporting HTTP2, Qt may send data to a server even if the TLS certificate doesn't match the redirected address. This occurs because Qt fails to validate the certificate against the redirected address, potentially sending data to an incorrect or malicious server.

Отчет

This flaw occurs because Qt does not properly validate the certificate against the redirected address, potentially leading to sensitive data being sent to an unintended or malicious server. Given the potential for significant data exposure, this issue is considered important.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Дополнительная информация

Статус:

Important
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=2295867qtbase: qtbase: Delay any communication until encrypted() can be responded to

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
12 месяцев назад

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

CVSS3: 8.6
nvd
12 месяцев назад

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

CVSS3: 5.9
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 8.6
debian
12 месяцев назад

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2. ...

rocky
11 месяцев назад

Important: qt5-qtbase security update

7.5 High

CVSS3