PT-2020-12515 · Qutebrowser+1 · Qutebrowser+1
Published
2020-05-07
·
Updated
2024-06-15
·
CVE-2020-11054
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
qutebrowser versions prior to 1.11.1
Description
After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (
colors.statusbar.url.warn.fg). However, when the affected website was subsequently loaded again, the URL was mistakenly displayed as green (colors.statusbar.url.success https). While the user already has seen a certificate error prompt at this point (or set content.ssl strict to false which is not recommended), this could still provide a false sense of security.Recommendations
If you are using qutebrowser version prior to 1.11.1, upgrade to version 1.11.1 or later.
If you are unable to upgrade, treat any host with a certificate exception as insecure, ignoring the URL color.
Alternatively, set
content.ssl strict to True (instead of 'ask'), preventing certificate exceptions.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Qutebrowser