CVE-2023-43090
Gnome-shell: screenshot tool allows viewing open windows when session is locked
Severity Score
5.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.
Se encontró una vulnerabilidad en GNOME Shell. La pantalla de bloqueo de GNOME Shell permite a un usuario local no autenticado ver ventanas de la sesión de escritorio bloqueada mediante el uso de atajos de teclado para desbloquear la funcionalidad restringida de la herramienta de captura de pantalla.
*Credits:
Red Hat would like to thank Mickael Karatekin (SysDream) for reporting this issue.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-09-15 CVE Reserved
- 2023-09-19 CVE Published
- 2023-09-22 EPSS Updated
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://access.redhat.com/security/cve/CVE-2023-43090 | Third Party Advisory | |
https://bugzilla.redhat.com/show_bug.cgi?id=2239087 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/6990 | 2024-08-02 |
URL | Date | SRC |
---|---|---|
https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/2944 | 2024-07-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnome Search vendor "Gnome" | Gnome-shell Search vendor "Gnome" for product "Gnome-shell" | >= 43 < 43.9 Search vendor "Gnome" for product "Gnome-shell" and version " >= 43 < 43.9" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Gnome-shell Search vendor "Gnome" for product "Gnome-shell" | >= 44 < 44.5 Search vendor "Gnome" for product "Gnome-shell" and version " >= 44 < 44.5" | - |
Affected
| ||||||
Gnome Search vendor "Gnome" | Gnome-shell Search vendor "Gnome" for product "Gnome-shell" | 42 Search vendor "Gnome" for product "Gnome-shell" and version "42" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 37 Search vendor "Fedoraproject" for product "Fedora" and version "37" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 38 Search vendor "Fedoraproject" for product "Fedora" and version "38" | - |
Affected
|