Input validation error in discover - CVE-2021-28117

 

Input validation error in discover - CVE-2021-28117

Published: March 12, 2021


Vulnerability identifier: #VU51424
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28117
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to missing URI scheme validation. A remote attacker can pass specially crafted link to an SMB or NFS share and potentially bypass implemented security restrictions by tricking the Discover to follow such links.


Affected software

discover
Fedora
plasma-discover
plasma-systemmonitor
plasma-desktop
plasma-disks
plasma-drkonqi
plasma-firewall
plasma-integration
plasma-milou
plasma-nm
plasma-oxygen
plasma-pa
plasma-sdk
plasma-browser-integration
plasma-systemsettings
plasma-thunderbolt
plasma-vault
plasma-workspace
plasma-workspace-wallpapers
plymouth-kcm
plymouth-theme-breeze
polkit-kde
powerdevil
qqc2-breeze-style
sddm-kcm
xdg-desktop-portal-kde
kmenuedit
bluedevil
breeze-gtk
grub2-breeze-theme
kactivitymanagerd
kde-cli-tools
kde-gtk-config
kdecoration
kdeplasma-addons
kgamma
khotkeys
kinfocenter
plasma-breeze
kscreen
kscreenlocker
ksshaskpass
ksysguard
kwayland-integration
kwayland-server
kwin
kwrited
libkscreen-qt5
pam-kwallet
libksysguard

How to mitigate CVE-2021-28117

Install updates from vendor's website.

discover - addressed in versions 5.18.7, 5.21.3
plasma-discover - addressed in versions 5.21.2-3.fc34, 5.21.3-1.fc34
plasma-systemmonitor - update to 5.21.3-1.fc34
plasma-desktop - update to 5.21.3-1.fc34
plasma-disks - update to 5.21.3-1.fc34
plasma-drkonqi - update to 5.21.3-1.fc34
plasma-firewall - update to 5.21.3-1.fc34
plasma-integration - update to 5.21.3-1.fc34
plasma-milou - update to 5.21.3-1.fc34
plasma-nm - update to 5.21.3-1.fc34
plasma-oxygen - update to 5.21.3-1.fc34
plasma-pa - update to 5.21.3-1.fc34
plasma-sdk - update to 5.21.3-1.fc34
plasma-browser-integration - update to 5.21.3-1.fc34
plasma-systemsettings - update to 5.21.3-1.fc34
plasma-thunderbolt - update to 5.21.3-1.fc34
plasma-vault - update to 5.21.3-1.fc34
plasma-workspace - update to 5.21.3-1.fc34
plasma-workspace-wallpapers - update to 5.21.3-1.fc34
plymouth-kcm - update to 5.21.3-1.fc34
plymouth-theme-breeze - update to 5.21.3-1.fc34
polkit-kde - update to 5.21.3-1.fc34
powerdevil - update to 5.21.3-1.fc34
qqc2-breeze-style - update to 5.21.3-1.fc34
sddm-kcm - update to 5.21.3-1.fc34
xdg-desktop-portal-kde - update to 5.21.3-1.fc34
kmenuedit - update to 5.21.3-1.fc34
bluedevil - update to 5.21.3-1.fc34
breeze-gtk - update to 5.21.3-1.fc34
grub2-breeze-theme - update to 5.21.3-1.fc34
kactivitymanagerd - update to 5.21.3-1.fc34
kde-cli-tools - update to 5.21.3-1.fc34
kde-gtk-config - update to 5.21.3-1.fc34
kdecoration - update to 5.21.3-1.fc34
kdeplasma-addons - update to 5.21.3-1.fc34
kgamma - update to 5.21.3-1.fc34
khotkeys - update to 5.21.3-1.fc34
kinfocenter - update to 5.21.3-1.fc34
plasma-breeze - update to 5.21.3-1.fc34
kscreen - update to 5.21.3-1.fc34
kscreenlocker - update to 5.21.3-1.fc34
ksshaskpass - update to 5.21.3-1.fc34
ksysguard - update to 5.21.3-1.fc34
kwayland-integration - update to 5.21.3-1.fc34
kwayland-server - update to 5.21.3-1.fc34
kwin - update to 5.21.3-1.fc34
kwrited - update to 5.21.3-1.fc34
libkscreen-qt5 - update to 5.21.3-1.fc34
pam-kwallet - update to 5.21.3-1.fc34
libksysguard - update to 5.21.3.1-1.fc34

External References

Related Security Bulletins