{
  "threat_severity" : "Moderate",
  "public_date" : "2024-03-24T00:00:00Z",
  "bugzilla" : {
    "description" : "qt6: wasm component may access QNetworkReply header improperly",
    "id" : "2271518",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2271518"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
    "status" : "draft"
  },
  "cwe" : "CWE-825",
  "details" : [ "In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly (wasm). (Earlier and later versions are unaffected.)", "A flaw was found in the qt6 package where the WebAssembly (wasm) component may access the network reply header due to a dangling pointer. This issue may allow an attacker to gain access to restricted data, impacting data confidentiality and integrity." ],
  "statement" : "The packages `qt4` and `qt5` are not vulnerable to this flaw.",
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Affected",
    "package_name" : "qt6",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-30161\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-30161" ],
  "name" : "CVE-2024-30161",
  "csaw" : false
}