Rapid7 Vulnerability & Exploit Database

FreeBSD: VID-452D16BB-920D-11EA-9D20-18A6F7016652 (CVE-2020-11054): qutebrowser -- Reloading page with certificate errors shows a green URL

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

FreeBSD: VID-452D16BB-920D-11EA-9D20-18A6F7016652 (CVE-2020-11054): qutebrowser -- Reloading page with certificate errors shows a green URL

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
Published
05/02/2020
Created
05/12/2020
Added
05/10/2020
Modified
10/20/2020

Description

In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.warn.fg). However, when the affected website was subsequently loaded again, the URL was mistakenly displayed as green (colors.statusbar.url.success_https). While the user already has seen a certificate error prompt at this point (or set content.ssl_strict to false, which is not recommended), this could still provide a false sense of security. This has been fixed in 1.11.1 and 1.12.0. All versions of qutebrowser are believed to be affected, though versions before v0.11.x couldn't be tested. Backported patches for older versions (greater than or equal to 1.4.0 and less than or equal to 1.10.2) are available, but no further releases are planned.

Solution(s)

  • freebsd-upgrade-package-qutebrowser

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;