vulnerability
FreeBSD: VID-f5fa174d-19de-11ef-83d8-4ccc6adda413 (CVE-2024-36048): QtNetworkAuth -- predictable seeding of PRNG in QAbstractOAuth
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 10 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | May 24, 2024 | May 25, 2024 | Dec 10, 2025 |
Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
May 24, 2024
Added
May 25, 2024
Modified
Dec 10, 2025
Description
Andy Shaw reports: The OAuth1 implementation in QtNetworkAuth created nonces using a PRNG that was seeded with a predictable seed. This means that an attacker that can somehow control the time of the first OAuth1 flow of the process has a high chance of predicting the nonce used in said OAuth flow.
Solutions
freebsd-upgrade-package-qt5-networkauthfreebsd-upgrade-package-qt6-networkauth
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.