Vulnerability Details CVE-2023-32762
An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.3%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2023-32762
-
Qt
»
Qt
»
Version: 5.10.0
-
Qt
»
Qt
»
Version: 5.10.1
-
Qt
»
Qt
»
Version: 5.11.0
-
Qt
»
Qt
»
Version: 5.11.1
-
Qt
»
Qt
»
Version: 5.11.2
-
Qt
»
Qt
»
Version: 5.11.3
-
Qt
»
Qt
»
Version: 5.12.0
-
Qt
»
Qt
»
Version: 5.12.1
-
Qt
»
Qt
»
Version: 5.12.10
-
Qt
»
Qt
»
Version: 5.12.11
-
Qt
»
Qt
»
Version: 5.12.2
-
Qt
»
Qt
»
Version: 5.12.3
-
Qt
»
Qt
»
Version: 5.12.4
-
Qt
»
Qt
»
Version: 5.12.5
-
Qt
»
Qt
»
Version: 5.12.6
-
Qt
»
Qt
»
Version: 5.12.7
-
Qt
»
Qt
»
Version: 5.12.8
-
Qt
»
Qt
»
Version: 5.12.9
-
Qt
»
Qt
»
Version: 5.13.0
-
Qt
»
Qt
»
Version: 5.13.1
-
Qt
»
Qt
»
Version: 5.13.2
-
-
Qt
»
Qt
»
Version: 5.14.0
-
Qt
»
Qt
»
Version: 5.14.1
-
Qt
»
Qt
»
Version: 5.14.2
-
Qt
»
Qt
»
Version: 5.15.0
-
Qt
»
Qt
»
Version: 5.15.1
-
Qt
»
Qt
»
Version: 5.15.2
-
Qt
»
Qt
»
Version: 5.15.4
-
Qt
»
Qt
»
Version: 5.15.8
-
-
-
Qt
»
Qt
»
Version: 5.9.10
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:o:debian:debian_linux:10.0