Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-6790

Опубликовано: 08 фев. 2018
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kdebase-workspaceNot affected
Red Hat Enterprise Linux 7kdelibsFixedRHSA-2019:214106.08.2019
Red Hat Enterprise Linux 7kde-settingsFixedRHSA-2019:214106.08.2019
Red Hat Enterprise Linux 7kde-workspaceFixedRHSA-2019:214106.08.2019
Red Hat Enterprise Linux 7kmagFixedRHSA-2019:214106.08.2019
Red Hat Enterprise Linux 7virtuoso-opensourceFixedRHSA-2019:214106.08.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1543454kde-workspace: Missing sanitization of notifications allows to leak client IP address via IMG element

EPSS

Процентиль: 60%
0.00393
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 8 лет назад

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.

CVSS3: 5.3
nvd
около 8 лет назад

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.

CVSS3: 5.3
debian
около 8 лет назад

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataeng ...

CVSS3: 5.3
github
больше 3 лет назад

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.

oracle-oval
больше 6 лет назад

ELSA-2019-2141: kde-workspace security and bug fix update (LOW)

EPSS

Процентиль: 60%
0.00393
Низкий

4.3 Medium

CVSS3