PT-2024-14712 · Kde · Libksieve

Bib

·

Published

2024-04-28

·

Updated

2024-07-03

·

CVE-2023-52723

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions KDE libksieve versions prior to 23.03.80
Description The issue arises from a mistake in kmanagesieve/session.cpp where a username variable is accidentally assigned a password value, resulting in cleartext passwords being placed in server logs.
Recommendations For versions prior to 23.03.80, update to version 23.03.80 or later to resolve the issue. As a temporary workaround, consider restricting access to server logs to minimize the risk of password exposure.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-52723
DLA-3809-1

Affected Products

Libksieve