Flawed polkit authorization checks in blueman allowed any user with access to the D-Bus system bus to trigger certain network configuration logic in blueman without authentication (boo#1083066).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2018-0414.json"