Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2020-17489 | First vendor Publication | 2020-08-11 |
Vendor | Cve | Last vendor Modification | 2021-03-26 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N | |||
---|---|---|---|
Overall CVSS Score | 4.3 | ||
Base Score | 4.3 | Environmental Score | 4.3 |
impact SubScore | 3.6 | Temporal Score | 4.3 |
Exploitabality Sub Score | 0.7 | ||
Attack Vector | Physical | Attack Complexity | Low |
Privileges Required | None | User Interaction | Required |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | None | Availability Impact | None |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:M/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 1.9 | Attack Range | Local |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 3.4 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment upon a logout. (If the password were never shown in cleartext, only the password length is revealed.) |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17489 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-522 | Insufficiently Protected Credentials (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
Sources (Detail)
Alert History
Date | Informations |
---|---|
2022-05-12 01:48:19 |
|
2021-05-04 13:51:06 |
|
2021-04-22 03:02:37 |
|
2021-03-26 21:23:10 |
|
2020-11-07 17:22:53 |
|
2020-09-15 21:23:14 |
|
2020-09-14 09:22:47 |
|
2020-09-02 17:23:13 |
|
2020-08-12 17:22:54 |
|
2020-08-12 05:22:58 |
|