Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-52723

Опубликовано: 29 апр. 2024
Источник: debian
EPSS Низкий

Описание

In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libkf5ksievefixed4:22.12.3-2package
libkf5ksievefixed4:22.12.3-1+deb12u1bookwormpackage
libkf5ksievefixed4:20.08.3-1+deb11u1bullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2024/04/25/1

  • Fixed by: https://invent.kde.org/pim/libksieve/-/commit/6b460ba93ac4ac503ba039d0b788ac7595120db1 (v23.03.80)

EPSS

Процентиль: 24%
0.0008
Низкий

Связанные уязвимости

CVSS3: 7.1
ubuntu
почти 2 года назад

In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value.

CVSS3: 7.1
nvd
почти 2 года назад

In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value.

CVSS3: 7.1
github
почти 2 года назад

In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value.

EPSS

Процентиль: 24%
0.0008
Низкий