Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-36472

Опубликовано: 28 мая 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior.

A vulnerability was found in GNOME Shell. A portal helper can be launched automatically without user confirmation based on the network responses provided by an adversary.

Отчет

Although this vulnerability may be triggered without user interaction required, it needs an attacker to control the local network and perform a man in the middle attack. That would then open a vector of attack through a web portal that could run malicious javascript code, but the attack would still need to chain other vulnerabilities to be able to harm the host, such as memory safety vulnerabilities and web process sandbox escaping. Hence this issue was rated as Moderate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7gnome-shellOut of support scope
Red Hat Enterprise Linux 8gnome-shellFixedRHSA-2024:529813.08.2024
Red Hat Enterprise Linux 9gnome-shellFixedRHSA-2024:911412.11.2024
Red Hat Enterprise Linux 9.4 Extended Update Supportgnome-shellFixedRHSA-2024:991519.11.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-83
https://bugzilla.redhat.com/show_bug.cgi?id=2283750gnome-shell: code execution in portal helper

EPSS

Процентиль: 6%
0.00029
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 года назад

In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior.

CVSS3: 6.5
nvd
около 1 года назад

In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior.

CVSS3: 6.5
debian
около 1 года назад

In GNOME Shell through 45.7, a portal helper can be launched automatic ...

suse-cvrf
11 месяцев назад

Security update for gnome-shell

suse-cvrf
11 месяцев назад

Security update for gnome-shell

EPSS

Процентиль: 6%
0.00029
Низкий

7.5 High

CVSS3