CVE-2018-6790

Description

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.393

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2019:2141)Low: security and bug fix update kde-workspace-debuginfo-4.11.19-13.el7.i686.rpmLinux
(RHSA-2019:2141)Low: security and bug fix update kde-workspace-debuginfo-4.11.19-13.el7.x86_64.rpmLinux
(RHSA-2019:2141)Low: security and bug fix update kdelibs-debuginfo-4.14.8-10.el7.i686.rpmLinux
(RHSA-2019:2141)Low: security and bug fix update kdelibs-debuginfo-4.14.8-10.el7.x86_64.rpmLinux
(RHSA-2019:2141)Low: security and bug fix update kmag-debuginfo-4.10.5-4.el7.x86_64.rpmLinux
(RHSA-2019:2141)Low: security and bug fix update virtuoso-opensource-debuginfo-6.1.6-7.el7.x86_64.rpmLinux
Kcm_colors update (ELSA-2019-2141) kcm_colors-4.11.19-13.el7.x86_64.rpmLinux
Kde-settings update (ELSA-2019-2141) kde-settings-19-23.9.0.1.el7.noarch.rpmLinux
Kde-settings-ksplash update (ELSA-2019-2141) kde-settings-ksplash-19-23.9.0.1.el7.noarch.rpmLinux
Kde-settings-plasma update (ELSA-2019-2141) kde-settings-plasma-19-23.9.0.1.el7.noarch.rpmLinux
Kde-settings-pulseaudio update (ELSA-2019-2141) kde-settings-pulseaudio-19-23.9.0.1.el7.noarch.rpmLinux
Kde-style-oxygen update (ELSA-2019-2141) kde-style-oxygen-4.11.19-13.el7.i686.rpmLinux
Kde-style-oxygen update (ELSA-2019-2141) kde-style-oxygen-4.11.19-13.el7.x86_64.rpmLinux
Kde-workspace update (ELSA-2019-2141) kde-workspace-4.11.19-13.el7.x86_64.rpmLinux
Kde-workspace-devel update (ELSA-2019-2141) kde-workspace-devel-4.11.19-13.el7.i686.rpmLinux
Kde-workspace-devel update (ELSA-2019-2141) kde-workspace-devel-4.11.19-13.el7.x86_64.rpmLinux
Kde-workspace-libs update (ELSA-2019-2141) kde-workspace-libs-4.11.19-13.el7.i686.rpmLinux
Kde-workspace-libs update (ELSA-2019-2141) kde-workspace-libs-4.11.19-13.el7.x86_64.rpmLinux
Kdelibs update (ELSA-2019-2141) kdelibs-4.14.8-10.el7.i686.rpmLinux
Kdelibs update (ELSA-2019-2141) kdelibs-4.14.8-10.el7.x86_64.rpmLinux
Kdelibs-common update (ELSA-2019-2141) kdelibs-common-4.14.8-10.el7.x86_64.rpmLinux
Kdelibs-devel update (ELSA-2019-2141) kdelibs-devel-4.14.8-10.el7.i686.rpmLinux
Kdelibs-devel update (ELSA-2019-2141) kdelibs-devel-4.14.8-10.el7.x86_64.rpmLinux
Kdelibs-ktexteditor update (ELSA-2019-2141) kdelibs-ktexteditor-4.14.8-10.el7.i686.rpmLinux
Kdelibs-ktexteditor update (ELSA-2019-2141) kdelibs-ktexteditor-4.14.8-10.el7.x86_64.rpmLinux
Kgreeter-plugins update (ELSA-2019-2141) kgreeter-plugins-4.11.19-13.el7.x86_64.rpmLinux
Khotkeys update (ELSA-2019-2141) khotkeys-4.11.19-13.el7.x86_64.rpmLinux
Khotkeys-libs update (ELSA-2019-2141) khotkeys-libs-4.11.19-13.el7.i686.rpmLinux
Khotkeys-libs update (ELSA-2019-2141) khotkeys-libs-4.11.19-13.el7.x86_64.rpmLinux
Kinfocenter update (ELSA-2019-2141) kinfocenter-4.11.19-13.el7.x86_64.rpmLinux
Kmag update (ELSA-2019-2141) kmag-4.10.5-4.el7.x86_64.rpmLinux
Kmenuedit update (ELSA-2019-2141) kmenuedit-4.11.19-13.el7.x86_64.rpmLinux
Ksysguard update (ELSA-2019-2141) ksysguard-4.11.19-13.el7.x86_64.rpmLinux
Ksysguard-libs update (ELSA-2019-2141) ksysguard-libs-4.11.19-13.el7.i686.rpmLinux
Ksysguard-libs update (ELSA-2019-2141) ksysguard-libs-4.11.19-13.el7.x86_64.rpmLinux
Ksysguardd update (ELSA-2019-2141) ksysguardd-4.11.19-13.el7.x86_64.rpmLinux
Kwin update (ELSA-2019-2141) kwin-4.11.19-13.el7.x86_64.rpmLinux
Kwin-gles-libs update (ELSA-2019-2141) kwin-gles-libs-4.11.19-13.el7.i686.rpmLinux
Kwin-gles-libs update (ELSA-2019-2141) kwin-gles-libs-4.11.19-13.el7.x86_64.rpmLinux
Kwin-libs update (ELSA-2019-2141) kwin-libs-4.11.19-13.el7.i686.rpmLinux
Kwin-libs update (ELSA-2019-2141) kwin-libs-4.11.19-13.el7.x86_64.rpmLinux
Libkworkspace update (ELSA-2019-2141) libkworkspace-4.11.19-13.el7.i686.rpmLinux
Libkworkspace update (ELSA-2019-2141) libkworkspace-4.11.19-13.el7.x86_64.rpmLinux
Plasma-scriptengine-python update (ELSA-2019-2141) plasma-scriptengine-python-4.11.19-13.el7.x86_64.rpmLinux
Qt-settings update (ELSA-2019-2141) qt-settings-19-23.9.0.1.el7.noarch.rpmLinux
Virtuoso-opensource update (ELSA-2019-2141) virtuoso-opensource-6.1.6-7.el7.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234