Vulnerability Description
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qt | Qt | < 5.15.17 |
| Fedoraproject | Fedora | 39 |
Related Weaknesses (CWE)
References
- https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560317Patch
- https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560368Patch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproThird Party Advisory
- https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560317Patch
- https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560368Patch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproThird Party Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://lists.fedoraproject.org/archives/list/[email protected]
FAQ
What is CVE-2024-36048?
CVE-2024-36048 is a vulnerability with a CVSS score of 9.8 (CRITICAL). QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which ma...
How severe is CVE-2024-36048?
CVE-2024-36048 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-36048?
Check the references section above for vendor advisories and patch information. Affected products include: Qt Qt, Fedoraproject Fedora.