Local Credential Retrieval Vulnerability in GNOME Keyring by GNOME
CVE-2018-19358

7.8HIGH

Key Information:

Vendor

Gnome

Vendor
CVE Published:
18 November 2018

What is CVE-2018-19358?

The GNOME Keyring, in versions up to 3.28.2, presents a vulnerability that enables local users to access sensitive login credentials through a Secret Service API call and the D-Bus interface, provided that the keyring is unlocked. This issue arises due to the lack of stringent D-Bus protection mechanisms, which should ideally prevent untrusted applications from accessing the user's session bus socket. Although GNOME has disputed this issue under their security model, the potential for credential exposure poses significant risks for users, particularly in multi-user environments.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.