VulnerabilityModified
CVE-2023-43090
A vulnerability was found in GNOME Shell.
MEDIUM 5.5EPSS 0.31%
Does this matter?
Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.31% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- gnome/gnome-shell · fedoraproject/fedora
- Source
- patrick@puiterwijk.org
References
- https://access.redhat.com/security/cve/CVE-2023-43090Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2239087Issue Tracking, Third Party Advisory
- https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/6990Exploit, Issue Tracking, Patch, Vendor Advisory
- https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/2944Patch, Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-43090Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2239087Issue Tracking, Third Party Advisory
- https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/6990Exploit, Issue Tracking, Patch, Vendor Advisory
- https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/2944Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.