CVE-2024-36472
published 2024-05-28CVE-2024-36472: In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary…
PriorityP426medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.30%
22.1th percentile
In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnome-shell | < gnome-shell 47.0-3 (forky) | gnome-shell 47.0-3 (forky) |
| gnome | gnome-shell | >= 0 < 47.0-3 | 47.0-3 |
| gnome | gnome-shell | >= 0 < 47.0-3 | 47.0-3 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNOME Shell vulnerability
vendor_ubuntu·2024-08-15
CVE-2024-36472 GNOME Shell vulnerability
Title: GNOME Shell vulnerability
Summary: GNOME Shell could allow unintended access to network services.
It was discovered that GNOME Shell incorrectly opened the portal helper
automatically when detecting a captive network portal. A remote attacker
could possibly use this issue to load arbitrary web pages containing
JavaScript, leading to resource consumption or other attacks.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
gnome-shell: code execution in portal helper
vendor_redhat·2024-05-28·CVSS 6.5
CVE-2024-36472 [MEDIUM] CWE-83 gnome-shell: code execution in portal helper
gnome-shell: code execution in portal helper
In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior.
A vulnerability was found in GNOME Shell. A portal helper can be launched automatically without user confirmation based on the network responses provided by an adversary.
Statement: Although this vulnerability may be triggered without user interaction required, it needs an attacker to control the local network and perform a man in the middle attack. That would then open a vector of at
Debian
CVE-2024-36472: gnome-shell - In GNOME Shell through 45.7, a portal helper can be launched automatically (with...
vendor_debian·2024·CVSS 6.5
CVE-2024-36472 [MEDIUM] CVE-2024-36472: gnome-shell - In GNOME Shell through 45.7, a portal helper can be launched automatically (with...
In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 47.0-3)
sid: resolved (fixed in 47.0-3)
trixie: resolved (fixed in 47.0-3)
OSV
CVE-2024-36472: In GNOME Shell through 45
osv·2024-05-28·CVSS 6.5
CVE-2024-36472 [MEDIUM] CVE-2024-36472: In GNOME Shell through 45
In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-05-28
Published