Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28797
HistoryDec 22, 2020 - 8:09 p.m.

Authentication Bypass

2020-12-2220:09:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.001 Low

EPSS

Percentile

30.1%

gdm3 is vulnerable to timing attacks. The vulnerability exists through a race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication.

CPENameOperatorVersion
gdm3:sideq3.38.2-1
gdm3:bullseyeeq3.38.2-1