Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Flagged CVE for qbittorrent from (at least) Microsoft Defender #19738

Closed
staze opened this issue Oct 19, 2023 · 2 comments
Closed

Flagged CVE for qbittorrent from (at least) Microsoft Defender #19738

staze opened this issue Oct 19, 2023 · 2 comments
Labels
Duplicate Security Related to software vulnerability in qbt (don't overuse this) WebAPI WebAPI-related issues/changes WebUI WebUI-related issues/changes

Comments

@staze
Copy link

staze commented Oct 19, 2023

qBittorrent & operating system versions

qBittorrent: All macOS versions (at least)
OS: macOS

What is the problem?

Microsoft Defender for Endpoint is flagging all versions of qBittorrent as having a 9.8 CVE for having default web credentials rather than any randomization of password.

"All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the external program feature in the web user interface. This was reportedly exploited in the wild in March 2023."

https://nvd.nist.gov/vuln/detail/CVE-2023-30801

Steps to reproduce

None

Additional context

No response

Log(s) & preferences file(s)

No response

@sledgehammer999
Copy link
Member

For interest parties there is discussion in PR #18735 and to the linked issues inside it.
It is not necessary to merge that specific PR. You can use it as a base for your own implementation.

@sledgehammer999 sledgehammer999 added Security Related to software vulnerability in qbt (don't overuse this) WebUI WebUI-related issues/changes WebAPI WebAPI-related issues/changes labels Oct 19, 2023
@sledgehammer999
Copy link
Member

Addressed with #19777

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Duplicate Security Related to software vulnerability in qbt (don't overuse this) WebAPI WebAPI-related issues/changes WebUI WebUI-related issues/changes
Projects
None yet
Development

No branches or pull requests

3 participants