CVE-2020-12755: Low severity kde kio vulnerability
fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of a password.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this KDE kio-extras vulnerability?
The vulnerability ID for this KDE kio-extras vulnerability is CVE-2020-12755.
What is the title of this KDE kio-extras vulnerability?
The title of this KDE kio-extras vulnerability is fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of a password.
What is the severity of CVE-2020-12755?
The severity of CVE-2020-12755 is low, with a severity value of 3.3.
What is the affected software for CVE-2020-12755?
The affected software for CVE-2020-12755 is KDE kio-extras version up to and including 20.04.0.
How can I fix CVE-2020-12755?
To fix CVE-2020-12755, update to a version of KDE kio-extras that is higher than 20.04.0.