CVE-2020-17489Insufficiently Protected Credentials in Gnome-shell

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 64.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 11
Latest updateMay 24

Description

An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment upon a logout. (If the password were never shown in cleartext, only the password length is revealed.)

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 0.7 | Impact: 3.6

Affected Packages3 packages

Debiangnome/gnome-shell< 3.36.5-1+3
NVDgnome/gnome-shell3.36.4
NVDopensuse/leap15.2

Also affects: Debian Linux 9.0, Ubuntu Linux 20.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-vfpj-rcwj-86vm: An issue was discovered in certain configurations of GNOME gnome-shell through 32022-05-24
CVEList
CVE-2020-17489: An issue was discovered in certain configurations of GNOME gnome-shell through 32020-08-11
OSV
CVE-2020-17489: An issue was discovered in certain configurations of GNOME gnome-shell through 32020-08-11

📋Vendor Advisories

3
Ubuntu
GNOME Shell vulnerability2020-08-18
Red Hat
gnome-shell: Password from logged-out user may be shown on login screen2020-08-11
Debian
CVE-2020-17489: gnome-shell - An issue was discovered in certain configurations of GNOME gnome-shell through 3...2020

💬Community

2
Bugzilla
CVE-2020-17489 gnome-shell: Password from logged-out user may be shown on login screen2020-08-12
Bugzilla
CVE-2020-17489 gnome-shell: Password from logged-out user may be shown on login screen [fedora-all]2020-08-12
CVE-2020-17489 — Insufficiently Protected Credentials | cvebase