Bug 1225567 (CVE-2024-36472) - VUL-0: CVE-2024-36472: gnome-shell: In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), ...
Summary: VUL-0: CVE-2024-36472: gnome-shell: In GNOME Shell through 45.7, a portal hel...
Status: NEW
Alias: CVE-2024-36472
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P2 - High : Major
Target Milestone: ---
Assignee: xiaoguang wang
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/407967/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-36472:6.5:(AV:...
Keywords:
Depends on:
Blocks: 1227692
  Show dependency treegraph
 
Reported: 2024-05-29 08:24 UTC by SMASH SMASH
Modified: 2024-07-18 08:40 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-05-29 08:24:11 UTC
In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-36472
https://www.cve.org/CVERecord?id=CVE-2024-36472
https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/7688