5.5
CVSSv3

CVE-2023-43090

Published: 22/09/2023 Updated: 26/09/2023
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome gnome-shell

gnome gnome-shell 42

fedoraproject fedora 37

fedoraproject fedora 38

Vendor Advisories

Debian Bug report logs - #1052067 gnome-shell: CVE-2023-43090: screenshot tool allows viewing open windows when session is locked Package: src:gnome-shell; Maintainer for src:gnome-shell is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> D ...
Mickael Karatekin discovered that the GNOME session locking didn't restrict a keyboard shortcut used for taking screenshots in GNOME Screenshot which could result in information disclosure The oldstable distribution (bullseye) is not affected For the stable distribution (bookworm), this problem has been fixed in version 436-1~deb12u2 We recomme ...
Description<!---->A vulnerability was found in GNOME Shell GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot toolA vulnerability was found in GNOME Shell GNOME Shell's lock screen allows an unauthenticat ...