Bug 1868418 (CVE-2020-17489) - CVE-2020-17489 gnome-shell: Password from logged-out user may be shown on login screen
Summary: CVE-2020-17489 gnome-shell: Password from logged-out user may be shown on log...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2020-17489
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1868419 1874259
Blocks: 1868420
TreeView+ depends on / blocked
 
Reported: 2020-08-12 15:15 UTC by Michael Kaplan
Modified: 2022-05-11 05:45 UTC (History)
6 users (show)

Fixed In Version: gnome-shell 3.37.3
Clone Of:
Environment:
Last Closed: 2022-05-11 05:45:33 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2022:1814 0 None None None 2022-05-10 13:36:36 UTC

Description Michael Kaplan 2020-08-12 15:15:26 UTC
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment upon a logout. (If the password were never shown in cleartext, only the password length is revealed.)

References:

https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/2997

Comment 1 Michael Kaplan 2020-08-12 15:15:44 UTC
Created gnome-shell tracking bugs for this issue:

Affects: fedora-all [bug 1868419]

Comment 7 Todd Cullum 2020-08-31 19:32:42 UTC
Mitigation:

Do not use the "view password" context menu option when logging into gnome-shell.

Comment 10 Todd Cullum 2020-08-31 20:07:08 UTC
Statement:

This flaw does not affect gnome-shell as shipped with Red Hat Enterprise Linux 6 or 7. For 6, there is no option to view the password in the clear at login, and for 7, the login screen is killed upon login.

Comment 12 errata-xmlrpc 2022-05-10 13:36:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:1814 https://access.redhat.com/errata/RHSA-2022:1814

Comment 13 Product Security DevOps Team 2022-05-11 05:45:30 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-17489


Note You need to log in before you can comment on or make changes to this bug.