CVE-2020-24619

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
22/09/2020
Last modified:
21/07/2021

Description

In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::VerifyNone). A man-in-the-middle attacker could offer a spoofed download resource.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:meltytech:shotcut:*:*:*:*:*:*:*:* 20.09.13 (excluding)