CVE Vulnerabilities

CVE-2024-36472

Published: May 28, 2024 | Modified: May 28, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript codes behavior.

Affected Software

Name Vendor Start Version End Version
Gnome-shell Ubuntu devel *
Gnome-shell Ubuntu focal *
Gnome-shell Ubuntu jammy *
Gnome-shell Ubuntu mantic *
Gnome-shell Ubuntu noble *
Gnome-shell Ubuntu upstream *
Red Hat Enterprise Linux 8 RedHat gnome-shell-0:3.32.2-56.el8_10 *

References