« Volver al listado

CVE-2023-43090

Estado: ModificadaMedia (5.5)—

A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-43090",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-43090",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-04-19T17:28:47.369532Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "patrick@puiterwijk.org",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "patrick@puiterwijk.org",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "42.*",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "43.0",
              "lessThan": "43.9",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "44.0",
              "lessThan": "44.5",
              "versionType": "custom"
            }
          ],
          "packageName": "gnome-shell",
          "collectionURL": "https://gitlab.gnome.org/GNOME/gnome-shell",
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:gnome:gnome-shell:-:*:*:*:*:*:*:*"
          ],
          "vendor": "gnome",
          "product": "gnome-shell",
          "versions": [
            {
              "status": "unknown",
              "version": "-"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-09-22T06:15:09.810",
  "references": [
    {
      "url": "https://access.redhat.com/security/cve/CVE-2023-43090",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "patrick@puiterwijk.org"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2239087",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "patrick@puiterwijk.org"
    },
    {
      "url": "https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/6990",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "patrick@puiterwijk.org"
    },
    {
      "url": "https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/2944",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "patrick@puiterwijk.org"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2023-43090",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2239087",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/6990",
      "tags": [
        "Exploit",
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/2944",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool."
    },
    {
      "lang": "es",
      "value": "Se encontró una vulnerabilidad en GNOME Shell. La pantalla de bloqueo de GNOME Shell permite a un usuario local no autenticado ver ventanas de la sesión de escritorio bloqueada mediante el uso de atajos de teclado para desbloquear la funcionalidad restringida de la herramienta de captura de pantalla."
    }
  ],
  "lastModified": "2026-06-17T06:25:06.550",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7A51F9D-C630-4F19-8DED-9247B3C568B8",
              "versionEndExcluding": "43.9",
              "versionStartIncluding": "43"
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA677E16-529C-4D1D-BEF7-F8C63FFD69AF",
              "versionEndExcluding": "44.5",
              "versionStartIncluding": "44"
            },
            {
              "criteria": "cpe:2.3:a:gnome:gnome-shell:42:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C024C0D-E889-40F0-8888-DB1A0267A11A"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E30D0E6F-4AE8-4284-8716-991DFA48CC5D"
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC559B26-5DFC-4B7A-A27C-B77DE755DFF9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "patrick@puiterwijk.org"
}