An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-05-28T00:00:00

Updated: 2024-08-19T16:42:12.680Z

Reserved: 2023-05-15T00:00:00

Link: CVE-2023-32762

cve-icon Vulnrichment

Updated: 2024-08-02T15:25:37.052Z

cve-icon NVD

Status : Modified

Published: 2023-05-28T23:15:09.570

Modified: 2024-11-21T08:03:59.967

Link: CVE-2023-32762

cve-icon Redhat

No data.