cbcvebase.
CVE-2023-43090
published 2023-09-22

CVE-2023-43090: A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using…

PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.31%
23.4th percentile
A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiangnome-shell< gnome-shell 43.6-1~deb12u2 (bookworm)gnome-shell 43.6-1~deb12u2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
gnomegnome-shell
gnomegnome-shell>= 0 < 43.6-1~deb12u243.6-1~deb12u2
gnomegnome-shell>= 0 < 44.5-144.5-1
gnomegnome-shell>= 0 < 44.5-144.5-1
gnomegnome-shell>= 43 < 43.943.9
gnomegnome-shell>= 44 < 44.544.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.