PT-2021-17752 · Kde+1 · Kde Discover+1

Fabian Bräunlein

·

Published

2021-03-18

·

Updated

2024-10-15

·

CVE-2021-28117

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: KDE Discover versions prior to 5.21.3 KDE Discover versions prior to 5.18.7
Description: The issue arises from the automatic creation of links to potentially dangerous URLs based on the content of the store.kde.org web site. These URLs are neither https:// nor http://.
Recommendations: For versions prior to 5.21.3, update to version 5.21.3 or later. For versions prior to 5.18.7, update to version 5.18.7 or later.

Fix

Related Identifiers

ALT-PU-2021-1589
CVE-2021-28117
MGASA-2021-0146

Affected Products

Alt Linux
Kde Discover