CVE-2021-20315
published 2022-02-18CVE-2021-20315: A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list"…
PriorityP425medium6.1CVSS 3.1
AVPACLPRNUINSUCNIHAH
EPSS
0.20%
9.6th percentile
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system to kill existing applications and start new ones as the locked user, even if the session is still locked.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| centos | stream | — | — |
| debian | gnome-shell | — | — |
| gnome | gnome-shell | < 3.32.2 | 3.32.2 |
| gnome | gnome-shell | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv6.1MEDIUM
vendor_debian6.1LOW
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hpr5-wwh9-pjhf: A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window l
ghsa_unreviewed·2022-02-19
CVE-2021-20315 [MEDIUM] CWE-667 GHSA-hpr5-wwh9-pjhf: A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window l
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system to kill existing applications and start new ones as the locked user, even if the session is still locked.
OSV
CVE-2021-20315: A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window l
osv·2022-02-18·CVSS 6.1
CVE-2021-20315 [MEDIUM] CVE-2021-20315: A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window l
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system to kill existing applications and start new ones as the locked user, even if the session is still locked.
Red Hat
gnome-shell: locking protection bypass allow unauthorized user to kill existing applications or start new ones
vendor_redhat·2021-08-31·CVSS 6.1
CVE-2021-20315 [MEDIUM] CWE-667 gnome-shell: locking protection bypass allow unauthorized user to kill existing applications or start new ones
gnome-shell: locking protection bypass allow unauthorized user to kill existing applications or start new ones
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system to kill existing applications and start new ones as the locked user, even if the session is still locked.
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system to kill existing applications and start new ones as the locked user,
Debian
CVE-2021-20315: gnome-shell - A locking protection bypass flaw was found in some versions of gnome-shell as sh...
vendor_debian·2021·CVSS 6.1
CVE-2021-20315 [MEDIUM] CVE-2021-20315: gnome-shell - A locking protection bypass flaw was found in some versions of gnome-shell as sh...
A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "Application menu" or "Window list" GNOME extensions are enabled. This flaw allows a physical attacker who has access to a locked system to kill existing applications and start new ones as the locked user, even if the session is still locked.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-18
Published