5.3
CVSSv3

CVE-2023-32762

Published: 28/05/2023 Updated: 01/05/2024
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in Qt prior to 5.15.14, 6.x prior to 6.2.9, and 6.3.x up to and including 6.5.x prior to 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qt qt

Vendor Advisories

Debian Bug report logs - #1036702 qtbase-opensource-src-gles: CVE-2023-32763 Package: src:qtbase-opensource-src-gles; Maintainer for src:qtbase-opensource-src-gles is Debian Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 24 May 2023 13:54:02 UTC Severi ...
QT-based clients may mismatch HSTS headers (Strict-Transport-Security), which would prevent the client from switching to a secure HTTPS connection as requested by a server (CVE-2023-32762) ...