An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.
External References:
https://www.kde.org/info/security/advisory-20180208-1.txt
Created kde-workspace tracking bugs for this issue:
Affects: fedora-all [bug 1543470]
Created plasma-workspace tracking bugs for this issue:
Affects: fedora-all [bug 1543471]