1.9
CVSSv2

CVE-2020-17489

Published: 11/08/2020 Updated: 26/03/2021
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 4.3 | Impact Score: 3.6 | Exploitability Score: 0.7
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in certain configurations of GNOME gnome-shell up to and including 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment upon a logout. (If the password were never shown in cleartext, only the password length is revealed.)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gnome-shell

canonical ubuntu linux 20.04

debian debian linux 9.0

opensuse leap 15.2

Vendor Advisories

Debian Bug report logs - #968311 gnome-shell: CVE-2020-17489 Package: src:gnome-shell; Maintainer for src:gnome-shell is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 12 Aug 2020 19:57:02 UTC Severity: important Tags: securit ...