CVE-2020-12755 log

Source
Severity Low
Remote No
Type Insufficient validation
Description
fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option.  This may lead to unintended KWallet storage of the password.

This is considered a security issue by users who do not trust KWallet (e.g. because passwords can be read in KWalletManager, given physical access).
Group Package Affected Fixed Severity Status Ticket
AVG-1156 kio-extras 19.12.3-1 20.04.0-1 Low Fixed
References
https://kde.org/info/security/advisory-20200510-1.txt
https://commits.kde.org/kio-extras/d813cef3cecdec9af1532a40d677a203ff979145