Bug 487791

Summary: plasma-discover: permission grant user to act as root
Product: [Applications] Discover Reporter: Marco Righi <marco.righi>
Component: discoverAssignee: Plasma Bugs List <plasma-bugs-null>
Status: RESOLVED WORKSFORME    
Severity: major CC: aleixpol
Priority: NOR    
Version First Reported In: unspecified   
Target Milestone: ---   
Platform: Other   
OS: Linux   
Latest Commit: Version Fixed/Implemented In:
Sentry Crash Report:

Description Marco Righi 2024-05-30 12:01:43 UTC
SUMMARY


STEPS TO REPRODUCE
1.  ls -l $(which plasma-discover)


OBSERVED RESULT
452K -rwxr-xr-x 1 root root 450K 25 mag 22.42 /usr/bin/plasma-discover


EXPECTED RESULT
452K -rwx------ 1 root root 450K 25 mag 22.42 /usr/bin/plasma-discover


SOFTWARE/OS VERSIONS

Linux/KDE Plasma: 
(available in About System)
LSB Version:	n/a
Distributor ID:	EndeavourOS
Description:	EndeavourOS Linux
Release:	rolling
Codename:	rolling


KDE Plasma Version: 

plasmashell --version
plasmashell 6.0.5

KDE Frameworks Version: 


Qt Version: 
qmake --version
QMake version 3.1
Using Qt version 5.15.14 in /usr/lib

ADDITIONAL INFORMATION
Same security problem on Linux Manjaro

lsb_release -a
LSB Version:	n/a
Distributor ID:	ManjaroLinux
Description:	Manjaro Linux
Release:	24.0.1
Codename:	Wynsdey
Comment 1 Antonio Rojas 2024-05-30 12:30:19 UTC
Why is it a security issue to allow users to run Discover?
Comment 2 Bug Janitor Service 2024-06-14 03:47:15 UTC
Dear Bug Submitter,

This bug has been in NEEDSINFO status with no change for at least
15 days. Please provide the requested information as soon as
possible and set the bug status as REPORTED. Due to regular bug
tracker maintenance, if the bug is still in NEEDSINFO status with
no change in 30 days the bug will be closed as RESOLVED > WORKSFORME
due to lack of needed information.

For more information about our bug triaging procedures please read the
wiki located here:
https://community.kde.org/Guidelines_and_HOWTOs/Bug_triaging

If you have already provided the requested information, please
mark the bug as REPORTED so that the KDE team knows that the bug is
ready to be confirmed.

Thank you for helping us make KDE software even better for everyone!
Comment 3 Bug Janitor Service 2024-06-29 03:47:38 UTC
This bug has been in NEEDSINFO status with no change for at least
30 days. The bug is now closed as RESOLVED > WORKSFORME
due to lack of needed information.

For more information about our bug triaging procedures please read the
wiki located here:
https://community.kde.org/Guidelines_and_HOWTOs/Bug_triaging

Thank you for helping us make KDE software even better for everyone!