2.1
CVSSv2

CVE-2020-12755

Published: 09/05/2020 Updated: 21/07/2021
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras up to and including 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of a password.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kde kio-extras

Vendor Advisories

Debian Bug report logs - #960306 kio-extras: CVE-2020-12755 Package: src:kio-extras; Maintainer for src:kio-extras is Debian/Kubuntu Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 11 May 2020 17:09:02 UTC Severity: important Tags: security, upstre ...
fishProtocol::establishConnection in fish/fishcpp in KDE kio-extras through 20040 makes a cacheAuthentication call even if the user had not set the keepPassword option This may lead to unintended KWallet storage of the password This is considered a security issue by users who do not trust KWallet (eg because passwords can be read in KWalle ...