5
CVSSv2

CVE-2021-28117

Published: 20/03/2021 Updated: 28/12/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover prior to 5.21.3 automatically creates links to potentially dangerous URLs (that are neither nor ) based on the content of the store.kde.org web site. (5.18.7 is also a fixed version.)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kde discover

Vendor Advisories

A security issue has been found in Discover version 5212 Discover fetches the description and related texts of some applications/plugins from storekdeorg That text is displayed to the user, after turning into a clickable link any part of the text that looks like a link This is done for any kind of link, be it smb:// nfs:// etc when in fact ...