CVE-2021-28117: Discover: Missing URI scheme validation
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
plasma-discover (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Focal |
New
|
Undecided
|
Unassigned | ||
Groovy |
Won't Fix
|
Undecided
|
Unassigned | ||
Hirsute |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
https:/
https:/
KDE Project Security Advisory
=======
Title: Discover: Missing URI scheme validation
Risk Rating: Low
CVE: CVE-2021-28117
Versions: Discover >= 5.15.0 <= 5.21.3
Author: Aleix Pol Gonzalez <email address hidden>
Date: 10 March 2021
Overview
========
Discover fetches the description and related texts of some applications/
part of the text that looks like a link. This is done for any kind of link, be it smb:// nfs:// etc. when in fact it only makes sense for http/https links.
Impact
======
Opening links that the user has clicked on is not very problematic but can be used to chain to other attack vectors. Given the intended functionality of the feature is just for http/https links it makes sense to do that verification.
Workaround
==========
Only click on http/https links in Discover.
Solution
========
Install Plasma 5.21.3, 5.18.7 or apply these patches
Plasma 5.21: https:/
Plasma 5.18: https:/
Credits
=======
Thanks to Fabian Bräunlein for reporting the issue.
This bug was fixed in the package plasma-discover - 5.21.3-0ubuntu1
---------------
plasma-discover (5.21.3-0ubuntu1) hirsute; urgency=medium
* New upstream release (5.21.3)
- Fixes CVE-2021-28117: Discover: Missing URI scheme validation
(LP: #1918681)
-- Rik Mills <email address hidden> Tue, 16 Mar 2021 20:32:20 +0000