Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qjh4-6jqf-7749

Опубликовано: 12 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it will try running the LSP server binary in the directory of the file that was just opened (due to a misunderstanding of the QProcess API, that was never intended). This can be an untrusted directory.

The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it will try running the LSP server binary in the directory of the file that was just opened (due to a misunderstanding of the QProcess API, that was never intended). This can be an untrusted directory.

EPSS

Процентиль: 43%
0.00211
Низкий

7.8 High

CVSS3

Дефекты

CWE-20
CWE-427

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 4 года назад

The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it will try running the LSP server binary in the directory of the file that was just opened (due to a misunderstanding of the QProcess API, that was never intended). This can be an untrusted directory.

CVSS3: 7.8
nvd
почти 4 года назад

The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it will try running the LSP server binary in the directory of the file that was just opened (due to a misunderstanding of the QProcess API, that was never intended). This can be an untrusted directory.

CVSS3: 7.8
debian
почти 4 года назад

The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 a ...

CVSS3: 8.8
fstec
почти 4 года назад

Уязвимость плагина Language Server Protocol текстового редактора Kate, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

suse-cvrf
почти 4 года назад

Security update for libqt5-qtbase

EPSS

Процентиль: 43%
0.00211
Низкий

7.8 High

CVSS3

Дефекты

CWE-20
CWE-427