PatchSiren cyber security CVE debrief
CVE-2017-6504 Qbittorrent CVE debrief
CVE-2017-6504 affects qBittorrent WebUI versions before 3.3.11. The issue is that the WebUI did not set the X-Frame-Options header, which could allow clickjacking against users interacting with the interface. The NVD record classifies the issue with CVSS 3.0 6.1 (Medium) and identifies the vulnerable version range as qBittorrent up to 3.3.10. A vendor patch and release notes are referenced in the official advisories.
- Vendor
- Qbittorrent
- Product
- Unknown
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-06
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-06
- Advisory updated
- 2026-05-13
Who should care
Administrators and users running qBittorrent with WebUI enabled, especially those exposing it on a network where authenticated users could be tricked into interacting with framed content.
Technical summary
The vulnerability is a WebUI hardening failure: qBittorrent did not send the X-Frame-Options response header, leaving the interface more susceptible to clickjacking. According to the NVD metadata, the issue is reachable over the network and requires user interaction, with impact limited to low confidentiality and integrity effects. The official references point to a specific upstream commit and the project release notes for the fix.
Defensive priority
Medium. This is not a code-execution flaw, but it does affect an interactive web interface and can be abused through social engineering if the WebUI is reachable.
Recommended defensive actions
- Upgrade qBittorrent to version 3.3.11 or later.
- Verify that the WebUI is no longer served from affected versions listed by NVD (up to 3.3.10).
- Review WebUI deployment exposure and restrict access where possible.
- Confirm that browser-framing protections are present in the fixed release and remain intact after customization or reverse-proxy changes.
- Use the upstream release notes and commit reference to validate the patch in your environment.
Evidence notes
Primary evidence comes from the CVE description and NVD metadata: the WebUI lacked the X-Frame-Options header and was vulnerable before 3.3.11. The official references include the upstream patch commit and qBittorrent release notes. NVD also lists CVSS 3.0 vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N and a primary weakness mapping of CWE-20.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6504 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6504
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6504 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6504
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/qbittorrent/qBittorrent/commit/f5ad04766f4abaa78374ff03704316f8ce04627d
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.qbittorrent.org/news.php
[email protected] - Patch, Release Notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.