CVE-2023-43090
published 2023-09-22CVE-2023-43090: A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.31%
23.4th percentile
A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnome-shell | < gnome-shell 43.6-1~deb12u2 (bookworm) | gnome-shell 43.6-1~deb12u2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnome | gnome-shell | — | — |
| gnome | gnome-shell | >= 0 < 43.6-1~deb12u2 | 43.6-1~deb12u2 |
| gnome | gnome-shell | >= 0 < 44.5-1 | 44.5-1 |
| gnome | gnome-shell | >= 0 < 44.5-1 | 44.5-1 |
| gnome | gnome-shell | >= 43 < 43.9 | 43.9 |
| gnome | gnome-shell | >= 44 < 44.5 | 44.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-43090: A vulnerability was found in GNOME Shell
osv·2023-09-22·CVSS 5.5
CVE-2023-43090 [MEDIUM] CVE-2023-43090: A vulnerability was found in GNOME Shell
A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.
GHSA
GHSA-6wp3-hhxh-4vfp: A vulnerability was found in GNOME Shell
ghsa_unreviewed·2023-09-22
CVE-2023-43090 [MEDIUM] CWE-862 GHSA-6wp3-hhxh-4vfp: A vulnerability was found in GNOME Shell
A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.
Ubuntu
GNOME Shell vulnerability
vendor_ubuntu·2023-09-21
CVE-2023-43090 GNOME Shell vulnerability
Title: GNOME Shell vulnerability
Summary: GNOME Shell could be made to expose sensitive information.
Mickael Karatekin discovered that GNOME Shell incorrectly allowed the
screenshot tool to view open windows when a session was locked. A local
attacker could possibly use this issue to obtain sensitive information.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
gnome-shell: Screenshot tool allows viewing open windows when session is locked
vendor_redhat·2023-09-15·CVSS 5.5
CVE-2023-43090 [MEDIUM] gnome-shell: Screenshot tool allows viewing open windows when session is locked
gnome-shell: Screenshot tool allows viewing open windows when session is locked
A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.
A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.
Package: gnome-shell (Red Hat Enterprise Linux 7) - Not affected
Package: gnome-shell (Red Hat Enterprise Linux 8) - Not affected
Package: gnome-shell (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2023-43090: gnome-shell - A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an un...
vendor_debian·2023·CVSS 5.5
CVE-2023-43090 [MEDIUM] CVE-2023-43090: gnome-shell - A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an un...
A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.
Scope: local
bookworm: resolved (fixed in 43.6-1~deb12u2)
bullseye: resolved
forky: resolved (fixed in 44.5-1)
sid: resolved (fixed in 44.5-1)
trixie: resolved (fixed in 44.5-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2023-43090https://bugzilla.redhat.com/show_bug.cgi?id=2239087https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/6990https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/2944https://access.redhat.com/security/cve/CVE-2023-43090https://bugzilla.redhat.com/show_bug.cgi?id=2239087https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/6990https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/2944
2023-09-22
Published