Authentication Cache Flaw in KDE Kio-Extras Affects User Password Storage
CVE-2020-12755

3.3LOW

Key Information:

Vendor

Kde

Vendor
CVE Published:
9 May 2020

What is CVE-2020-12755?

An improper authentication vulnerability exists in the fishProtocol's establishConnection function within KDE's kio-extras. This flaw allows the system to cache user credentials in KWallet without explicit user consent if the keepPassword option is not enabled. As a result, unauthorized applications may access sensitive passwords unintentionally stored, emphasizing the need for careful configuration of user authentication settings.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.