PT-2020-12515 · Qutebrowser+1 · Qutebrowser+1

Published

2020-05-07

·

Updated

2024-06-15

·

CVE-2020-11054

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions qutebrowser versions prior to 1.11.1
Description After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.warn.fg). However, when the affected website was subsequently loaded again, the URL was mistakenly displayed as green (colors.statusbar.url.success https). While the user already has seen a certificate error prompt at this point (or set content.ssl strict to false which is not recommended), this could still provide a false sense of security.
Recommendations If you are using qutebrowser version prior to 1.11.1, upgrade to version 1.11.1 or later. If you are unable to upgrade, treat any host with a certificate exception as insecure, ignoring the URL color. Alternatively, set content.ssl strict to True (instead of 'ask'), preventing certificate exceptions.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3156
CVE-2020-11054
GHSA-4RCQ-JV2F-898J
OPENSUSE-SU-2024:11292-1
PYSEC-2020-97

Affected Products

Alt Linux
Qutebrowser