CVE Vulnerabilities

CVE-2024-51774

Improper Certificate Validation

Published: Nov 02, 2024 | Modified: Nov 06, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.1 CRITICAL
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
QbittorrentQbittorrent*5.0.1 (excluding)
QbittorrentUbuntufocal*
QbittorrentUbuntuoracular*
QbittorrentUbuntuupstream*

Potential Mitigations

References