Home
MEDIUM: 6.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:LDefault status
unaffected
Any version before 26.04.1
affected
Description
Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.
Problem types
CWE-829 Inclusion of Functionality from Untrusted Control Sphere
Product status
Any version before 26.04.1
References
commits.kde.org/.../94042ddd259551e4a7a5f6672329752972c84685
commits.kde.org/.../c3999aacc6da54756f3df8aab03b900459562ecd