An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.
{
"binaries": [
{
"binary_name": "libkworkspace5-5",
"binary_version": "4:5.5.5.2-0ubuntu1.1"
},
{
"binary_name": "libplasma-geolocation-interface5",
"binary_version": "4:5.5.5.2-0ubuntu1.1"
},
{
"binary_name": "libtaskmanager5",
"binary_version": "4:5.5.5.2-0ubuntu1.1"
},
{
"binary_name": "libweather-ion7",
"binary_version": "4:5.5.5.2-0ubuntu1.1"
},
{
"binary_name": "plasma-workspace",
"binary_version": "4:5.5.5.2-0ubuntu1.1"
},
{
"binary_name": "plasma-workspace-dev",
"binary_version": "4:5.5.5.2-0ubuntu1.1"
},
{
"binary_name": "plasma-workspace-wayland",
"binary_version": "4:5.5.5.2-0ubuntu1.1"
},
{
"binary_name": "sddm-theme-breeze",
"binary_version": "4:5.5.5.2-0ubuntu1.1"
}
]
}