CVE-2020-12755: Kde Kio-Extras

Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.

fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of a password.

Affected products

  • Kde Kio-Extras: up to and including 20.04.0

Published 2020-05-09. Last modified 2026-06-17.