First published: Sat May 09 2020(Updated: )
fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of a password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDE kio-extras | <=20.04.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this KDE kio-extras vulnerability is CVE-2020-12755.
The title of this KDE kio-extras vulnerability is fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of a password.
The severity of CVE-2020-12755 is low, with a severity value of 3.3.
The affected software for CVE-2020-12755 is KDE kio-extras version up to and including 20.04.0.
To fix CVE-2020-12755, update to a version of KDE kio-extras that is higher than 20.04.0.