CVE-2023-32762
5.3
MEDIUM
CVSS 3.1
EPSS 0.14%
Description
An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.
How to fix CVE-2023-32762
To remediate CVE-2023-32762, upgrade the affected package to a fixed version below.
- —upgrade to 6.4.2+dfsg-9 or later
- —upgrade to 5.15.2+dfsg-9+deb11u1 or later
Is CVE-2023-32762 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 6.4.2+dfsg-9
- from 0, < 5.15.2+dfsg-9+deb11u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |