Releases213
Frequency3 weeks 22 hours
Last Release
Stars14.2K
cross-platform (Qt), open-source (GPLv3) video editor

CVE History

CVEPublishedCVSS v3CVSS v2
5.9 MEDIUM4.3 MEDIUM

In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::VerifyNone). A man-in-the-middle attacker could offer a spoofed download resource.