Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-17489
HistoryAug 11, 2020 - 12:00 a.m.

CVE-2020-17489

2020-08-1100:00:00
ubuntu.com
ubuntu.com
10
cve-2020-17489; logout password vulnerability; cleartext password

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

44.8%

An issue was discovered in certain configurations of GNOME gnome-shell
through 3.36.4. When logging out of an account, the password box from the
login dialog reappears with the password still visible. If the user had
decided to have the password shown in cleartext at login time, it is then
visible for a brief moment upon a logout. (If the password were never shown
in cleartext, only the password length is revealed.)

Bugs

Notes

Author Note
mdeslaur per upstream bug, appears to have been introduced in 3.34
OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchgnome-shell< 3.36.4-1ubuntu1~20.04.2UNKNOWN

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

44.8%