ZeroHour

CVE-2020-17489

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p45
Published
()
Modified
Description

An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment upon a logout. (If the password were never shown in cleartext, only the password length is revealed.)

Vendors
gnomecanonicaldebianopensuse
Products
gnome-shell, ubuntu linux, debian linux, leap
Weakness
CWE-522
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.