CVE-2023-32762: Medium severity f5 big-ip and big-iq centralized management vulnerability
An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.
Other sources
Qt could allow a remote attacker to bypass security restrictions, caused by incorrectly parsing the strict-transport-security (HSTS) header. By sending a specially crafted request, an attacker could exploit this vulnerability to cause unencrypted connections to be established.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-32762.
What is the severity rating of CVE-2023-32762?
The severity rating of CVE-2023-32762 is medium with a severity value of 5.3.
What is affected by CVE-2023-32762?
Qt versions before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1 are affected by CVE-2023-32762.
How does CVE-2023-32762 exploit the vulnerability?
CVE-2023-32762 exploits the vulnerability by incorrectly parsing the strict-transport-security (HSTS) header in Qt Network, allowing unencrypted connections to be established even when explicitly prohibited by the server.
Are there any references related to CVE-2023-32762?
Yes, you can find references related to CVE-2023-32762 at the following links: [Link 1](https://lists.qt-project.org/pipermail/announce/2023-May/000414.html), [Link 2](https://github.com/qt/qtbase/commit/1b736a815be0222f4b24289cf17575fc15707305), [Link 3](https://codereview.qt-project.org/c/qt/qtbase/+/476140).