UBUNTU-CVE-2021-28117

Source
https://ubuntu.com/security/CVE-2021-28117
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-28117.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2021-28117
Related
Published
2021-03-20T21:15:00Z
Modified
2024-10-15T14:08:05Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are neither https:// nor http://) based on the content of the store.kde.org web site. (5.18.7 is also a fixed version.)

References

Affected packages

Ubuntu:Pro:16.04:LTS / plasma-discover

Package

Name
plasma-discover
Purl
pkg:deb/ubuntu/plasma-discover?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.5.4-0ubuntu1
5.5.5-0ubuntu1
5.5.5-0ubuntu2
5.6.2-1ubuntu1
5.6.2-1ubuntu1.1

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:Pro:18.04:LTS / plasma-discover

Package

Name
plasma-discover
Purl
pkg:deb/ubuntu/plasma-discover?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.10.5-0ubuntu1
5.11.3-0ubuntu1
5.11.4-0ubuntu1
5.11.5-0ubuntu1
5.12.0-0ubuntu1
5.12.0-0ubuntu2
5.12.1-0ubuntu1
5.12.1-0ubuntu2
5.12.2-0ubuntu1
5.12.2-0ubuntu2
5.12.3-0ubuntu1
5.12.4-0ubuntu1
5.12.5-0ubuntu0.1
5.12.5.1-0ubuntu0.1
5.12.6-0ubuntu0.1
5.12.7-0ubuntu0.1
5.12.8-0ubuntu0.1

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:20.04:LTS / plasma-discover

Package

Name
plasma-discover
Purl
pkg:deb/ubuntu/plasma-discover?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.16.5-0ubuntu1
5.17.2-0ubuntu1
5.17.3-0ubuntu1
5.17.4-0ubuntu1
5.17.5-0ubuntu1
5.17.90-0ubuntu1
5.17.90-0ubuntu2
5.18.0-0ubuntu1
5.18.1-0ubuntu1
5.18.2-0ubuntu1
5.18.2-0ubuntu2
5.18.3-0ubuntu1
5.18.4.1-0ubuntu1
5.18.5-0ubuntu0.1
5.18.7-0ubuntu0.1

Ecosystem specific

{
    "ubuntu_priority": "low"
}