Bug ID 1223506
Summary VUL-0: CVE-2023-52723: libksieve: password exposure in server logs
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/403447/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee lbeltrame@kde.org
Reporter smash_bz@suse.de
QA Contact security-team@suse.de
CC carlos.lopez@suse.com
Target Milestone ---
Found By Security Response Team
Blocker ---

In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext
password in server logs because a username variable is accidentally given a
password value.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-52723
https://www.cve.org/CVERecord?id=CVE-2023-52723
https://invent.kde.org/pim/libksieve/-/commit/6b460ba93ac4ac503ba039d0b788ac7595120db1
https://invent.kde.org/pim/libksieve/-/tags/v23.03.80
http://www.openwall.com/lists/oss-security/2024/04/25/1


You are receiving this mail because: