Bug 2283545 (CVE-2023-50977)
| Summary: | CVE-2023-50977 gnome-shell: Shell Captive Portal Hijack | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | jgrulich |
| Target Milestone: | --- | Keywords: | Reopened, Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | GNOME Shell 45.2 | Doc Type: | If docs needed, set a value |
| Doc Text: |
A flaw was found In gnome-shell. The GNOME Network Manager and GNOME Shell Portal Helper connectivity checks send DNS checks that, if intercepted, may be used to launch a GNOME Captive Portal in a WebKitGTK browser and load arbitrary HTML and Javascript code.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2025-05-12 13:43:04 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2283555 | ||
| Bug Blocks: | 2283546 | ||
|
Description
Pedro Sampaio
2024-05-27 20:48:30 UTC
Created gnome-shell tracking bugs for this issue: Affects: fedora-all [bug 2283555] This vulnerability is classified as moderate severity rather than high because it requires a specific and controlled environment to be exploited effectively. The attacker needs to perform DNS hijacking within the same local network, which limits the scope of potential targets. Additionally, the exploit depends on the GNOME Captive Portal automatically opening a WebKitGTK browser, which, while a default behavior, may not be universally applicable across all GNOME configurations. Furthermore, modern web browsers use sandboxing as a mechanism to contain malicious activity, significantly reducing the potential impact of the exploit. This sandboxing mitigates the risk of the attack affecting other parts of the system, thus lowering the severity of this flaw to moderate. The exploitation vector, while technically feasible, involves multiple steps that reduce the likelihood of widespread, automated attacks. Thus, the impact, while serious, is confined to scenarios with network control and specific GNOME settings, justifying its moderate severity classification. My understanding is that this issue was fixed in gnome-shell 47+ with [1], which we have in Fedora 41 and newer, therefore this issue can be closed. [1] - https://gitlab.gnome.org/GNOME/gnome-shell/-/commit/4ab1ccf3f21b754ce4be77becf5df46084a893d8 I'm sorry, I accidentally closed the tracker instead of the Fedora bug. Reopening again. |