In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior. https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/7688
Created gnome-shell tracking bugs for this issue: Affects: fedora-all [bug 2283751]
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:5298 https://access.redhat.com/errata/RHSA-2024:5298
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:9114 https://access.redhat.com/errata/RHSA-2024:9114
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2024:9915 https://access.redhat.com/errata/RHSA-2024:9915