PatchSiren cyber security CVE debrief
CVE-2017-6504 Qbittorrent CVE debrief
CVE-2017-6504 affects qBittorrent WebUI versions before 3.3.11. The issue is that the WebUI did not set the X-Frame-Options header, which could allow clickjacking against users interacting with the interface. The NVD record classifies the issue with CVSS 3.0 6.1 (Medium) and identifies the vulnerable version range as qBittorrent up to 3.3.10. A vendor patch and release notes are referenced in the official advisories.
- Vendor
- Qbittorrent
- Product
- CVE-2017-6504
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-06
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-06
- Advisory updated
- 2026-05-13
Who should care
Administrators and users running qBittorrent with WebUI enabled, especially those exposing it on a network where authenticated users could be tricked into interacting with framed content.
Technical summary
The vulnerability is a WebUI hardening failure: qBittorrent did not send the X-Frame-Options response header, leaving the interface more susceptible to clickjacking. According to the NVD metadata, the issue is reachable over the network and requires user interaction, with impact limited to low confidentiality and integrity effects. The official references point to a specific upstream commit and the project release notes for the fix.
Defensive priority
Medium. This is not a code-execution flaw, but it does affect an interactive web interface and can be abused through social engineering if the WebUI is reachable.
Recommended defensive actions
- Upgrade qBittorrent to version 3.3.11 or later.
- Verify that the WebUI is no longer served from affected versions listed by NVD (up to 3.3.10).
- Review WebUI deployment exposure and restrict access where possible.
- Confirm that browser-framing protections are present in the fixed release and remain intact after customization or reverse-proxy changes.
- Use the upstream release notes and commit reference to validate the patch in your environment.
Evidence notes
Primary evidence comes from the CVE description and NVD metadata: the WebUI lacked the X-Frame-Options header and was vulnerable before 3.3.11. The official references include the upstream patch commit and qBittorrent release notes. NVD also lists CVSS 3.0 vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N and a primary weakness mapping of CWE-20.
Official resources
-
CVE-2017-6504 CVE record
CVE.org
-
CVE-2017-6504 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Patch, Release Notes
Publicly disclosed in the CVE record on 2017-03-06. The record was later modified on 2026-05-13, but that does not change the original issue date.