MGASA-2021-0146

    Dashboard / Vulnerabilities / MGASA-2021-0146

    MGASA-2021-0146

    Published: 18 Mar 2021Last Modified: 16 Apr 2026
    Upstream:

    Summary: Updated discover package fixes a security vulnerability

    Details: Discover fetches the description and related texts of some applications/plugins from store.kde.org. That text is displayed to the user, after turning into a clickable link any part of the text that looks like a link. This is done for any kind of link, be it smb:// nfs:// etc. when in fact it only makes sense for http/https links. Opening links that the user has clicked on is not very problematic but can be used to chain to other attack vectors. Given the intended functionality of the feature is just for http/https links it makes sense to do that verification (CVE-2021-28117).

    Affected packages

    Package

    Name: discover

    Purl: pkg:rpm/mageia/discover?arch=source&distro=mageia-7

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -5.15.4-2.2.mga7

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    MGASA-2021-0146 | CVE-DB