VDB

DEBIAN-CVE-2023-32762

DEBIAN-CVE-2023-32762 PUBLISHED CVSS 5.300000190734863 MEDIUM

An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.

Risk Scores

CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected Products

VendorProductVersions
Debian:11qtbase-opensource-src5.15.2+dfsg-9, 5.15.2+dfsg-9, 0
Debian:13qt6-base0, 0, 0
Debian:12qtbase-opensource-src0, 0, 0
Debian:13qtbase-opensource-src0, 0, 0
Debian:14qtbase-opensource-src0, 0, 0
Debian:14qt6-base0, 0, 0
Debian:12qt6-base0, 0, 0

Timeline

  • May 28, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›