Description
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.
CVSS vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 0.9 | Impact: 3.4Attack Vector: Physical
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: Low
Availability: Low
Affected Packages4 packages
Also affects: Ubuntu Linux 18.04, 18.10
🔴Vulnerability Details
4OSVgnome-shell vulnerabilities↗2024-10-03 ▶ GHSAGHSA-jh4v-7q79-jf56: It was discovered that the gnome-shell lock screen since version 3↗2022-05-13 ▶ CVEListCVE-2019-3820: It was discovered that the gnome-shell lock screen since version 3↗2019-02-06 ▶ OSVCVE-2019-3820: It was discovered that the gnome-shell lock screen since version 3↗2019-02-06 ▶ 📋Vendor Advisories
4UbuntuGNOME Shell vulnerabilities↗2024-10-03 ▶ UbuntuGNOME Shell vulnerability↗2019-05-06 ▶ Red Hatgnome-shell: partial lock screen bypass↗2019-02-05 ▶ DebianCVE-2019-3820: gnome-shell - It was discovered that the gnome-shell lock screen since version 3.15.91 did not...↗2019 ▶ 💬Community
2BugzillaCVE-2019-3820 gnome-shell: partial lock screen bypass [fedora-all]↗2019-02-06 ▶ BugzillaCVE-2019-3820 gnome-shell: partial lock screen bypass↗2019-01-25 ▶