CVE Vulnerabilities

CVE-2019-3825

Improper Authentication

Published: Feb 06, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.4
MEDIUM
Source:
NVD
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
6.3 MODERATE
CVSS:3.0/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which time they would gain access to the logged-in users session.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Gnome_display_managerGnome*3.31.4 (excluding)
Red Hat Enterprise Linux 8RedHataccountsservice-0:0.6.50-8.el8*
Red Hat Enterprise Linux 8RedHatappstream-data-0:8-20191129.el8*
Red Hat Enterprise Linux 8RedHatbaobab-0:3.28.0-4.el8*
Red Hat Enterprise Linux 8RedHatclutter-0:1.26.2-8.el8*
Red Hat Enterprise Linux 8RedHatevince-0:3.28.4-4.el8*
Red Hat Enterprise Linux 8RedHatgdm-1:3.28.3-29.el8*
Red Hat Enterprise Linux 8RedHatgjs-0:1.56.2-4.el8*
Red Hat Enterprise Linux 8RedHatgnome-boxes-0:3.28.5-8.el8*
Red Hat Enterprise Linux 8RedHatgnome-control-center-0:3.28.2-19.el8*
Red Hat Enterprise Linux 8RedHatgnome-menus-0:3.13.3-11.el8*
Red Hat Enterprise Linux 8RedHatgnome-online-accounts-0:3.28.2-1.el8*
Red Hat Enterprise Linux 8RedHatgnome-remote-desktop-0:0.1.6-8.el8*
Red Hat Enterprise Linux 8RedHatgnome-session-0:3.28.1-8.el8*
Red Hat Enterprise Linux 8RedHatgnome-settings-daemon-0:3.32.0-9.el8*
Red Hat Enterprise Linux 8RedHatgnome-shell-0:3.32.2-14.el8*
Red Hat Enterprise Linux 8RedHatgnome-software-0:3.30.6-3.el8*
Red Hat Enterprise Linux 8RedHatgnome-terminal-0:3.28.3-1.el8*
Red Hat Enterprise Linux 8RedHatgnome-tweaks-0:3.28.1-7.el8*
Red Hat Enterprise Linux 8RedHatgsettings-desktop-schemas-0:3.32.0-4.el8*
Red Hat Enterprise Linux 8RedHatgtk3-0:3.22.30-5.el8*
Red Hat Enterprise Linux 8RedHatgvfs-0:1.36.2-8.el8*
Red Hat Enterprise Linux 8RedHatLibRaw-0:0.19.5-1.el8*
Red Hat Enterprise Linux 8RedHatlibvncserver-0:0.9.11-14.el8*
Red Hat Enterprise Linux 8RedHatlibxslt-0:1.1.32-4.el8*
Red Hat Enterprise Linux 8RedHatmozjs52-0:52.9.0-2.el8*
Red Hat Enterprise Linux 8RedHatmozjs60-0:60.9.0-4.el8*
Red Hat Enterprise Linux 8RedHatmutter-0:3.32.2-34.el8*
Red Hat Enterprise Linux 8RedHatnautilus-0:3.28.1-12.el8*
Red Hat Enterprise Linux 8RedHatvala-0:0.40.19-1.el8*
Red Hat Enterprise Linux 8RedHatvinagre-0:3.22.0-21.el8*
Red Hat Enterprise Linux 8RedHataccountsservice-0:0.6.50-8.el8*
Red Hat Enterprise Linux 8RedHatappstream-data-0:8-20191129.el8*
Red Hat Enterprise Linux 8RedHatbaobab-0:3.28.0-4.el8*
Red Hat Enterprise Linux 8RedHatclutter-0:1.26.2-8.el8*
Red Hat Enterprise Linux 8RedHatevince-0:3.28.4-4.el8*
Red Hat Enterprise Linux 8RedHatgdm-1:3.28.3-29.el8*
Red Hat Enterprise Linux 8RedHatgjs-0:1.56.2-4.el8*
Red Hat Enterprise Linux 8RedHatgnome-boxes-0:3.28.5-8.el8*
Red Hat Enterprise Linux 8RedHatgnome-control-center-0:3.28.2-19.el8*
Red Hat Enterprise Linux 8RedHatgnome-menus-0:3.13.3-11.el8*
Red Hat Enterprise Linux 8RedHatgnome-online-accounts-0:3.28.2-1.el8*
Red Hat Enterprise Linux 8RedHatgnome-remote-desktop-0:0.1.6-8.el8*
Red Hat Enterprise Linux 8RedHatgnome-session-0:3.28.1-8.el8*
Red Hat Enterprise Linux 8RedHatgnome-settings-daemon-0:3.32.0-9.el8*
Red Hat Enterprise Linux 8RedHatgnome-shell-0:3.32.2-14.el8*
Red Hat Enterprise Linux 8RedHatgnome-software-0:3.30.6-3.el8*
Red Hat Enterprise Linux 8RedHatgnome-terminal-0:3.28.3-1.el8*
Red Hat Enterprise Linux 8RedHatgnome-tweaks-0:3.28.1-7.el8*
Red Hat Enterprise Linux 8RedHatgsettings-desktop-schemas-0:3.32.0-4.el8*
Red Hat Enterprise Linux 8RedHatgtk3-0:3.22.30-5.el8*
Red Hat Enterprise Linux 8RedHatgvfs-0:1.36.2-8.el8*
Red Hat Enterprise Linux 8RedHatLibRaw-0:0.19.5-1.el8*
Red Hat Enterprise Linux 8RedHatlibvncserver-0:0.9.11-14.el8*
Red Hat Enterprise Linux 8RedHatlibxslt-0:1.1.32-4.el8*
Red Hat Enterprise Linux 8RedHatmozjs52-0:52.9.0-2.el8*
Red Hat Enterprise Linux 8RedHatmozjs60-0:60.9.0-4.el8*
Red Hat Enterprise Linux 8RedHatmutter-0:3.32.2-34.el8*
Red Hat Enterprise Linux 8RedHatnautilus-0:3.28.1-12.el8*
Red Hat Enterprise Linux 8RedHatvala-0:0.40.19-1.el8*
Red Hat Enterprise Linux 8RedHatvinagre-0:3.22.0-21.el8*
Gdm3Ubuntubionic*
Gdm3Ubuntucosmic*
Gdm3Ubuntudevel*
Gdm3Ubuntudisco*
Gdm3Ubuntueoan*
Gdm3Ubuntuesm-apps/xenial*
Gdm3Ubuntuesm-infra/bionic*
Gdm3Ubuntuesm-infra/focal*
Gdm3Ubuntufocal*
Gdm3Ubuntugroovy*
Gdm3Ubuntuhirsute*
Gdm3Ubuntuimpish*
Gdm3Ubuntujammy*
Gdm3Ubuntukinetic*
Gdm3Ubuntulunar*
Gdm3Ubuntumantic*
Gdm3Ubuntunoble*
Gdm3Ubuntuoracular*
Gdm3Ubuntuplucky*
Gdm3Ubuntuquesting*
Gdm3Ubuntuxenial*

Potential Mitigations

References