Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-6410
HistoryMar 02, 2017 - 6:59 a.m.

Authentication flaw

2017-03-0206:59:00
PRIOn knowledge base
www.prio-n.com
7

5.2 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.3%

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.

CPENameOperatorVersion
kdelibsle4.14.29
kiole5.31

5.2 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.3%