cbcvebase.
CVE-2017-8288
published 2017-04-27

CVE-2017-8288: gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these…

PriorityP346high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
2.96%
85.8th percentile
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. It all depends on what extensions a user has enabled. The problem is caused by lack of exception handling in js/ui/extensionSystem.js.

Affected

18 ranges
VendorProductVersion rangeFixed in
debiangnome-shell< gnome-shell 3.22.3-3 (bookworm)gnome-shell 3.22.3-3 (bookworm)
gnomegnome-shell
gnomegnome-shell
gnomegnome-shell
gnomegnome-shell
gnomegnome-shell
gnomegnome-shell
gnomegnome-shell
gnomegnome-shell
gnomegnome-shell
gnomegnome-shell
gnomegnome-shell
gnomegnome-shell
gnomegnome-shell>= 0 < 3.22.3-33.22.3-3
gnomegnome-shell>= 0 < 3.22.3-33.22.3-3
gnomegnome-shell>= 0 < 3.22.3-33.22.3-3
gnomegnome-shell>= 0 < 3.22.3-33.22.3-3
gnomegnome-shell>= 0 < 3.18.5-0ubuntu0.3+esm13.18.5-0ubuntu0.3+esm1

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.