Remote Code Execution (RCE) Affecting qbittorrent/qbittorrent package, versions [,5.0.1)
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.06% (29th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UNMANAGED-QBITTORRENTQBITTORRENT-8323740
- published 3 Nov 2024
- disclosed 2 Nov 2024
- credit Unknown
Introduced: 2 Nov 2024
New CVE-2024-51774 Open this link in a new tabHow to fix?
Upgrade qbittorrent/qbittorrent
to version 5.0.1 or higher.
Overview
Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to improper handling of certificate validation errors. An attacker can intercept and manipulate secure communications by exploiting the lack of proper validation.