CVE-2024-36048
published 2024-05-18CVE-2024-36048: QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.97%
58.0th percentile
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qt6-networkauth | < qt6-networkauth 6.7.2-2 (forky) | qt6-networkauth 6.7.2-2 (forky) |
| debian | qtnetworkauth-everywhere-src | < qt6-networkauth 6.7.2-2 (forky) | qt6-networkauth 6.7.2-2 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| qt | qt | < 5.15.17 | 5.15.17 |
| qt | qt | >= 6.0.0 < 6.2.13 | 6.2.13 |
| qt | qt | >= 6.3.0 < 6.5.6 | 6.5.6 |
| qt | qt | >= 6.6.0 < 6.7.1 | 6.7.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-36048: QAbstractOAuth in Qt Network Authorization in Qt before 5
osv·2024-05-18·CVSS 9.8
CVE-2024-36048 [CRITICAL] CVE-2024-36048: QAbstractOAuth in Qt Network Authorization in Qt before 5
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
GHSA
GHSA-r8x8-rv8c-j266: QAbstractOAuth in Qt Network Authorization in Qt before 5
ghsa_unreviewed·2024-05-18
CVE-2024-36048 [CRITICAL] CWE-335 GHSA-r8x8-rv8c-j266: QAbstractOAuth in Qt Network Authorization in Qt before 5
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
Red Hat
qtnetworkauth: badly seeded PRNG may result in guessable values
vendor_redhat·2024-05-18·CVSS 9.8
CVE-2024-36048 [CRITICAL] CWE-337 qtnetworkauth: badly seeded PRNG may result in guessable values
qtnetworkauth: badly seeded PRNG may result in guessable values
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
A predictable seed vulnerability was found in QtNetworkAuth. QAbstractOAuth uses only the time to seed the PRNG, which may result in guessable values.
Package: qt6-qtnetworkauth (Red Hat Enterprise Linux 10) - Affected
Debian
CVE-2024-36048: qt6-networkauth - QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2....
vendor_debian·2024·CVSS 9.8
CVE-2024-36048 [CRITICAL] CVE-2024-36048: qt6-networkauth - QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2....
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
Scope: local
bookworm: open
forky: resolved (fixed in 6.7.2-2)
sid: resolved (fixed in 6.7.2-2)
trixie: resolved (fixed in 6.7.2-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560317https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560368https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGB6KUPJFQWUBKXVDPJUMAD6KNJJEWPW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZOOZZZSK5PNRHFGQMUGUHVYWLILFJCRS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZPHAI3DKDCIU6XLNS6PV6GFS2PHH3GZM/https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560317https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560368https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGB6KUPJFQWUBKXVDPJUMAD6KNJJEWPW/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZOOZZZSK5PNRHFGQMUGUHVYWLILFJCRS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZPHAI3DKDCIU6XLNS6PV6GFS2PHH3GZM/https://lists.fedoraproject.org/archives/list/[email protected]/message/RGB6KUPJFQWUBKXVDPJUMAD6KNJJEWPW/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZOOZZZSK5PNRHFGQMUGUHVYWLILFJCRS/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZPHAI3DKDCIU6XLNS6PV6GFS2PHH3GZM/
2024-05-18
Published