{"id":"UBUNTU-CVE-2021-28117","details":"libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are neither https:// nor http://) based on the content of the store.kde.org web site. (5.18.7 is also a fixed version.)","modified":"2025-10-24T04:50:13Z","published":"2021-03-20T21:15:00Z","upstream":["CVE-2021-28117"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-28117"},{"type":"REPORT","url":"https://kde.org/info/security/advisory-20210310-1.txt"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-28117"}],"affected":[{"package":{"name":"plasma-discover","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/plasma-discover@5.6.2-1ubuntu1.1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.5.4-0ubuntu1","5.5.5-0ubuntu1","5.5.5-0ubuntu2","5.6.2-1ubuntu1","5.6.2-1ubuntu1.1"],"ecosystem_specific":{"binaries":[{"binary_name":"muon-discover","binary_version":"4:5.6.2-1ubuntu1.1"},{"binary_version":"4:5.6.2-1ubuntu1.1","binary_name":"muon-notifier"},{"binary_name":"muon-updater","binary_version":"4:5.6.2-1ubuntu1.1"},{"binary_name":"plasma-discover","binary_version":"5.6.2-1ubuntu1.1"},{"binary_name":"plasma-discover-common","binary_version":"5.6.2-1ubuntu1.1"},{"binary_name":"plasma-discover-private","binary_version":"5.6.2-1ubuntu1.1"},{"binary_name":"plasma-discover-updater","binary_version":"5.6.2-1ubuntu1.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-28117.json"}},{"package":{"name":"plasma-discover","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/plasma-discover@5.12.8-0ubuntu0.1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.10.5-0ubuntu1","5.11.3-0ubuntu1","5.11.4-0ubuntu1","5.11.5-0ubuntu1","5.12.0-0ubuntu1","5.12.0-0ubuntu2","5.12.1-0ubuntu1","5.12.1-0ubuntu2","5.12.2-0ubuntu1","5.12.2-0ubuntu2","5.12.3-0ubuntu1","5.12.4-0ubuntu1","5.12.5-0ubuntu0.1","5.12.5.1-0ubuntu0.1","5.12.6-0ubuntu0.1","5.12.7-0ubuntu0.1","5.12.8-0ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"muon-discover","binary_version":"4:5.12.8-0ubuntu0.1"},{"binary_name":"muon-notifier","binary_version":"4:5.12.8-0ubuntu0.1"},{"binary_name":"muon-updater","binary_version":"4:5.12.8-0ubuntu0.1"},{"binary_name":"plasma-discover","binary_version":"5.12.8-0ubuntu0.1"},{"binary_version":"5.12.8-0ubuntu0.1","binary_name":"plasma-discover-common"},{"binary_name":"plasma-discover-flatpak-backend","binary_version":"5.12.8-0ubuntu0.1"},{"binary_name":"plasma-discover-snap-backend","binary_version":"5.12.8-0ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-28117.json"}},{"package":{"name":"plasma-discover","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/plasma-discover@5.18.7-0ubuntu0.1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.16.5-0ubuntu1","5.17.2-0ubuntu1","5.17.3-0ubuntu1","5.17.4-0ubuntu1","5.17.5-0ubuntu1","5.17.90-0ubuntu1","5.17.90-0ubuntu2","5.18.0-0ubuntu1","5.18.1-0ubuntu1","5.18.2-0ubuntu1","5.18.2-0ubuntu2","5.18.3-0ubuntu1","5.18.4.1-0ubuntu1","5.18.5-0ubuntu0.1","5.18.7-0ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"plasma-discover","binary_version":"5.18.7-0ubuntu0.1"},{"binary_name":"plasma-discover-backend-flatpak","binary_version":"5.18.7-0ubuntu0.1"},{"binary_name":"plasma-discover-backend-fwupd","binary_version":"5.18.7-0ubuntu0.1"},{"binary_name":"plasma-discover-backend-snap","binary_version":"5.18.7-0ubuntu0.1"},{"binary_name":"plasma-discover-common","binary_version":"5.18.7-0ubuntu0.1"},{"binary_name":"plasma-discover-flatpak-backend","binary_version":"5.18.7-0ubuntu0.1"},{"binary_name":"plasma-discover-snap-backend","binary_version":"5.18.7-0ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-28117.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"Ubuntu","score":"low"}]}