CVE-2023-43090

A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnome:gnome-shell:*:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gnome-shell:*:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gnome-shell:42:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

History

03 Jul 2024, 01:41

Type Values Removed Values Added
CWE CWE-862

26 Sep 2023, 13:10

Type Values Removed Values Added
CPE cpe:2.3:a:gnome:gnome-shell:42:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gnome-shell:*:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
References (MISC) https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/6990 - (MISC) https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/6990 - Exploit, Issue Tracking, Patch, Vendor Advisory
References (MISC) https://access.redhat.com/security/cve/CVE-2023-43090 - (MISC) https://access.redhat.com/security/cve/CVE-2023-43090 - Third Party Advisory
References (MISC) https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/2944 - (MISC) https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/2944 - Patch, Vendor Advisory
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2239087 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2239087 - Issue Tracking, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Fedoraproject
Fedoraproject fedora
Gnome
Gnome gnome-shell
CWE NVD-CWE-noinfo

22 Sep 2023, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-22 06:15

Updated : 2024-07-03 01:41


NVD link : CVE-2023-43090

Mitre link : CVE-2023-43090

CVE.ORG link : CVE-2023-43090


JSON object : View

Products Affected

fedoraproject

  • fedora

gnome

  • gnome-shell
CWE
NVD-CWE-noinfo CWE-862

Missing Authorization