{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-43090","assignerOrgId":"92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5","state":"PUBLISHED","assignerShortName":"fedora","dateReserved":"2023-09-15T07:17:59.705Z","datePublished":"2023-09-22T05:02:08.801Z","dateUpdated":"2024-08-02T19:37:23.406Z"},"containers":{"cna":{"title":"Gnome-shell: screenshot tool allows viewing open windows when session is locked","metrics":[{"other":{"content":{"value":"Moderate","namespace":"https://access.redhat.com/security/updates/classification/"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS"}],"descriptions":[{"lang":"en","value":"A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool."}],"affected":[{"versions":[{"status":"affected","version":"0","lessThan":"42.*","versionType":"custom"},{"status":"affected","version":"43.0","lessThan":"43.9","versionType":"custom"},{"status":"affected","version":"44.0","lessThan":"44.5","versionType":"custom"}],"packageName":"gnome-shell","collectionURL":"https://gitlab.gnome.org/GNOME/gnome-shell","defaultStatus":"unaffected"}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2023-43090","tags":["vdb-entry","x_refsource_REDHAT"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2239087","name":"RHBZ#2239087","tags":["issue-tracking","x_refsource_REDHAT"]},{"url":"https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/6990"},{"url":"https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/2944"}],"datePublic":"2023-09-15T00:00:00.000Z","timeline":[{"lang":"en","time":"2023-09-15T00:00:00.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2023-09-15T00:00:00.000Z","value":"Made public."}],"credits":[{"lang":"en","value":"Red Hat would like to thank Mickael Karatekin (SysDream) for reporting this issue."}],"providerMetadata":{"orgId":"92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5","shortName":"fedora","dateUpdated":"2024-04-19T13:43:44.302Z"}},"adp":[{"title":"CISA ADP Vulnrichment","metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2023-43090","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-04-19T17:28:47.369532Z"}}}],"affected":[{"cpes":["cpe:2.3:a:gnome:gnome-shell:-:*:*:*:*:*:*:*"],"vendor":"gnome","product":"gnome-shell","versions":[{"status":"unknown","version":"-"}],"defaultStatus":"unknown"}],"problemTypes":[{"descriptions":[{"lang":"en","type":"CWE","cweId":"CWE-862","description":"CWE-862 Missing Authorization"}]}],"providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-04T17:25:59.938Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T19:37:23.406Z"},"title":"CVE Program Container","references":[{"url":"https://access.redhat.com/security/cve/CVE-2023-43090","tags":["vdb-entry","x_refsource_REDHAT","x_transferred"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2239087","name":"RHBZ#2239087","tags":["issue-tracking","x_refsource_REDHAT","x_transferred"]},{"url":"https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/6990","tags":["x_transferred"]},{"url":"https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/2944","tags":["x_transferred"]}]}]}}