CVE-2020-12755: Kde Kio-Extras
Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.
fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of a password.
Affected products
- Kde Kio-Extras: up to and including 20.04.0
Published 2020-05-09. Last modified 2026-06-17.