CVE-2020-12755 - log back

CVE-2020-12755 edited at 11 May 2020 18:09:49
Severity
- Unknown
+ Low
Remote
- Unknown
+ Local
Type
- Unknown
+ Insufficient validation
Description
+ fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of the password.
+
+ This is considered a security issue by users who do not trust KWallet (e.g. because passwords can be read in KWalletManager, given physical access).
References
+ https://kde.org/info/security/advisory-20200510-1.txt
+ https://commits.kde.org/kio-extras/d813cef3cecdec9af1532a40d677a203ff979145
Notes
CVE-2020-12755 created at 11 May 2020 18:08:55