Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q5wj-8g6x-hgg2

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.

EPSS

Процентиль: 60%
0.00393
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 8 лет назад

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.

CVSS3: 4.3
redhat
около 8 лет назад

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.

CVSS3: 5.3
nvd
около 8 лет назад

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.

CVSS3: 5.3
debian
около 8 лет назад

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataeng ...

oracle-oval
больше 6 лет назад

ELSA-2019-2141: kde-workspace security and bug fix update (LOW)

EPSS

Процентиль: 60%
0.00393
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200