CVE-2020-12755 log
Source |
|
Severity | Low |
Remote | No |
Type | Insufficient validation |
Description | fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of the password. This is considered a security issue by users who do not trust KWallet (e.g. because passwords can be read in KWalletManager, given physical access). |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-1156 | kio-extras | 19.12.3-1 | 20.04.0-1 | Low | Fixed |
References |
---|
https://kde.org/info/security/advisory-20200510-1.txt https://commits.kde.org/kio-extras/d813cef3cecdec9af1532a40d677a203ff979145 |