VDB

CVE-2020-27837

CVE-2020-27837 PUBLISHED CVSS 6.400000095367432 MEDIUM

A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.

EPSS 0.22% · 13.3th percentile

Risk Scores

CVSS 3.1
6.400000095367432
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.22%
13.3th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSgdm30, 3.34.1-1ubuntu1, 3.36.3-0ubuntu0.20.04.3
Ubuntu:22.04:LTSgdm30, 41~rc-0ubuntu2, 41.0-3ubuntu1

Timeline

  • Dec 28, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 28, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 4, 2022 EPSS Score
  • Sep 6, 2022 EPSS Score
  • Nov 7, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›