Vulnerability Description
fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of a password.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kde | Kio-Extras | <= 20.04.0 |
References
- https://commits.kde.org/kio-extras/d813cef3cecdec9af1532a40d677a203ff979145Mailing ListPatchVendor Advisory
- https://commits.kde.org/kio-extras/d813cef3cecdec9af1532a40d677a203ff979145Mailing ListPatchVendor Advisory
FAQ
What is CVE-2020-12755?
CVE-2020-12755 is a vulnerability with a CVSS score of 3.3 (LOW). fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended ...
How severe is CVE-2020-12755?
CVE-2020-12755 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12755?
Check the references section above for vendor advisories and patch information. Affected products include: Kde Kio-Extras.