Red Hat Bugzilla – Bug 1543454
CVE-2018-6790 kde-workspace: Missing sanitization of notifications allows to leak client IP address via IMG element
Last modified: 2018-04-30 17:47:58 EDT
An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element. External References: https://www.kde.org/info/security/advisory-20180208-1.txt
Created kde-workspace tracking bugs for this issue: Affects: fedora-all [bug 1543470] Created plasma-workspace tracking bugs for this issue: Affects: fedora-all [bug 1543471]
*** Bug 1542676 has been marked as a duplicate of this bug. ***
Upstream commit: https://cgit.kde.org/plasma-workspace.git/commit/?h=Plasma/5.8&id=5bc696b5abcdb460c1017592e80b2d7f6ed3107c Discussion around the upstream patch: https://phabricator.kde.org/D10188