6.4
CVSSv3

CVE-2020-27837

Published: 28/12/2020 Updated: 30/12/2020
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 6.4 | Impact Score: 5.9 | Exploitability Score: 0.5
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A flaw was found in GDM in versions before 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gnome display manager

Vendor Advisories

A security issue was found in gdm before version 33821 A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication This is similar to CVE-2017-12164, but requires more difficult conditions to exploit ...