CVE Vulnerabilities

CVE-2023-34410

Improper Certificate Validation

Published: Jun 05, 2023 | Modified: Mar 20, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Debian_linuxDebian10.0 (including)10.0 (including)
Red Hat Enterprise Linux 8RedHatqt5-qtbase-0:5.15.3-5.el8*
Red Hat Enterprise Linux 9RedHatqt5-0:5.15.9-1.el9*
Qt4-x11Ubuntubionic*
Qt4-x11Ubuntutrusty*
Qt4-x11Ubuntutrusty/esm*
Qt4-x11Ubuntuxenial*
Qt6-baseUbuntubionic*
Qt6-baseUbuntukinetic*
Qt6-baseUbuntulunar*
Qt6-baseUbuntumantic*
Qt6-baseUbuntuoracular*
Qt6-baseUbuntuplucky*
Qt6-baseUbuntutrusty*
Qt6-baseUbuntuxenial*
Qtbase-opensource-srcUbuntubionic*
Qtbase-opensource-srcUbuntuesm-apps/focal*
Qtbase-opensource-srcUbuntuesm-apps/jammy*
Qtbase-opensource-srcUbuntuesm-infra/bionic*
Qtbase-opensource-srcUbuntuesm-infra/xenial*
Qtbase-opensource-srcUbuntufocal*
Qtbase-opensource-srcUbuntujammy*
Qtbase-opensource-srcUbuntukinetic*
Qtbase-opensource-srcUbuntulunar*
Qtbase-opensource-srcUbuntumantic*
Qtbase-opensource-srcUbuntuoracular*
Qtbase-opensource-srcUbuntutrusty*
Qtbase-opensource-srcUbuntuupstream*
Qtbase-opensource-srcUbuntuxenial*
Qtbase-opensource-src-glesUbuntubionic*
Qtbase-opensource-src-glesUbuntufocal*
Qtbase-opensource-src-glesUbuntukinetic*
Qtbase-opensource-src-glesUbuntulunar*
Qtbase-opensource-src-glesUbuntumantic*
Qtbase-opensource-src-glesUbuntuoracular*
Qtbase-opensource-src-glesUbuntuplucky*
Qtbase-opensource-src-glesUbuntutrusty*
Qtbase-opensource-src-glesUbuntuxenial*

Potential Mitigations

References