Lucene search

K
rosalinuxROSA LABROSA-SA-2021-1846
HistoryJul 02, 2021 - 4:56 p.m.

Advisory ROSA-SA-2021-1846

2021-07-0216:56:49
ROSA LAB
abf.rosalinux.ru
11
gnome-shell
cobalt 7.9
security advisory
plain text
login dialog box
cve-2020-17489
medium.

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.001

Percentile

44.8%

Software: gnome-shell 3.28.3
OS: Cobalt 7.9

CVE-ID: CVE-2020-17489
CVE-Crit: MEDIUM
CVE-DESC: A problem was found in some GNOME gnome-shell configurations through 3.36.4. When logging out of an account, the password field in the login dialog box reappears, but the password is still displayed. If the user chose to have the password displayed in plain text while logged in, the password will be visible for a short time after logging out. (If the password has never been displayed in plain text, only the length of the password is displayed.)
CVE-STATUS: default
CVE-REV: default

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.001

Percentile

44.8%