Description
In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::VerifyNone). A man-in-the-middle attacker could offer a spoofed download resource.
References (2)
Core 2
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/mltframework/shotcut/commit/f008adc039642307f6ee3378d378cdb842e52c1d
Release Notes, Vendor Advisory x_refsource_confirm
https://shotcut.org/blog/new-release-200913/
Scores
CVSS v3
5.9
EPSS
0.0071
EPSS Percentile
48.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-295
Status
published
Products (1)
meltytech/shotcut
< 20.09.13
Published
Sep 22, 2020
Tracked Since
Feb 18, 2026