Related Vulnerabilities: CVE-2021-31855  

Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g. an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. This is not easily noticeable by the user because KMail does not display the decrypted content.

Severity Low

Remote Yes

Type Information disclosure

Description

Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g. an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. This is not easily noticeable by the user because KMail does not display the decrypted content.

AVG-1897 messagelib 21.04.0-1 21.04.0-2 Low Fixed

https://kde.org/info/security/advisory-20210429-1.txt
https://invent.kde.org/pim/messagelib/commit/3b5b171e91ce78b966c98b1292a1bcbc8d984799