PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-6504 Qbittorrent CVE debrief

CVE-2017-6504 affects qBittorrent WebUI versions before 3.3.11. The issue is that the WebUI did not set the X-Frame-Options header, which could allow clickjacking against users interacting with the interface. The NVD record classifies the issue with CVSS 3.0 6.1 (Medium) and identifies the vulnerable version range as qBittorrent up to 3.3.10. A vendor patch and release notes are referenced in the official advisories.

Vendor
Qbittorrent
Product
Unknown
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2017-03-06
Original CVE updated
2026-05-13
Advisory published
2017-03-06
Advisory updated
2026-05-13

Who should care

Administrators and users running qBittorrent with WebUI enabled, especially those exposing it on a network where authenticated users could be tricked into interacting with framed content.

Technical summary

The vulnerability is a WebUI hardening failure: qBittorrent did not send the X-Frame-Options response header, leaving the interface more susceptible to clickjacking. According to the NVD metadata, the issue is reachable over the network and requires user interaction, with impact limited to low confidentiality and integrity effects. The official references point to a specific upstream commit and the project release notes for the fix.

Defensive priority

Medium. This is not a code-execution flaw, but it does affect an interactive web interface and can be abused through social engineering if the WebUI is reachable.

Recommended defensive actions

  • Upgrade qBittorrent to version 3.3.11 or later.
  • Verify that the WebUI is no longer served from affected versions listed by NVD (up to 3.3.10).
  • Review WebUI deployment exposure and restrict access where possible.
  • Confirm that browser-framing protections are present in the fixed release and remain intact after customization or reverse-proxy changes.
  • Use the upstream release notes and commit reference to validate the patch in your environment.

Evidence notes

Primary evidence comes from the CVE description and NVD metadata: the WebUI lacked the X-Frame-Options header and was vulnerable before 3.3.11. The official references include the upstream patch commit and qBittorrent release notes. NVD also lists CVSS 3.0 vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N and a primary weakness mapping of CWE-20.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-6504 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-6504

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-6504 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6504

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.