{"id":"MGASA-2021-0146","summary":"Updated discover package fixes a security vulnerability","details":"Discover fetches the description and related texts of some applications/plugins\nfrom store.kde.org. That text is displayed to the user, after turning into a\nclickable link any part of the text that looks like a link. This is done for\nany kind of link, be it smb:// nfs:// etc. when in fact it only makes sense for\nhttp/https links. Opening links that the user has clicked on is not very\nproblematic but can be used to chain to other attack vectors. Given the\nintended functionality of the feature is just for http/https links it makes\nsense to do that verification (CVE-2021-28117).\n","modified":"2026-02-04T02:24:51.972377Z","published":"2021-03-18T10:52:54Z","related":["CVE-2021-28117"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0146.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=28581"},{"type":"REPORT","url":"https://kde.org/info/security/advisory-20210310-1.txt"}],"affected":[{"package":{"name":"discover","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/discover?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.4-2.2.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0146.json"}},{"package":{"name":"discover","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/discover?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.20.4-3.1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0146.json"}}],"schema_version":"1.7.3","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}