gnome-keyring: login credentials retrieval via a Secret Service API call
Published Nov 18, 2018
7.8
HIGHCVSS 3.0
EPSS 0.56%
Description
GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML elements) are not used. NOTE: the vendor disputes this because, according to the security model, untrusted applications must not be allowed to access the user's session bus socket.
Affected products
No data.
- ≤ 3.28.2
No data.
Red Hat Enterprise Linux 5
gnome-keyring
Not affected
Red Hat Enterprise Linux 6
gnome-keyring
Not affected
Red Hat Enterprise Linux 7
gnome-keyring
Not affected
Red Hat Enterprise Linux 8
gnome-keyring
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | gnome-keyring | Not affected | n/a |
| Red Hat Enterprise Linux 6 | gnome-keyring | Not affected | n/a |
| Red Hat Enterprise Linux 7 | gnome-keyring | Not affected | n/a |
| Red Hat Enterprise Linux 8 | gnome-keyring | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat has determined that this flaw is not a security vulnerability pertaining to gnome-keyring as the underlying issue is that there is currently no way (except by using Flatkpak, sandboxing, containers, etc.) to completely separate user applications from each other, which in turn means it is possible for applications running in the same user session to gain access to each other's secrets.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
AV:L/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.56% (0.00558) | 44.51th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.56% (0.00558) | 45.31th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.04% (0.00043) | 10.12th | v3 (v2023.03.01) |
| Jun 20, 2024 | 0.04% (0.00043) | 9.83th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00043) | 7.83th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00890) | 30.33th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00890) | 12.04th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.44% (0.00444) | 10.84th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.44% (0.00444) | 0.00th | v1 |
References (9)
- https://access.redhat.com/security/cve/CVE-2018-19358 Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/gnome-keyring/+bug/1780365 ExploitIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1652194 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=1652194#c8
- https://github.com/sungjungk/keyring_crack ExploitThird Party Advisory
- https://gitlab.gnome.org/GNOME/gnome-keyring/-/issues/5#note_1876550
- https://nvd.nist.gov/vuln/detail/CVE-2018-19358
- https://www.cve.org/CVERecord?id=CVE-2018-19358
- https://www.youtube.com/watch?v=Do4E9ZQaPck ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-19358 | Vendor Advisory | |
| https://bugs.launchpad.net/ubuntu/+source/gnome-keyring/+bug/1780365 | ExploitIssue TrackingThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1652194 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1652194#c8 | ||
| https://github.com/sungjungk/keyring_crack | ExploitThird Party Advisory | |
| https://gitlab.gnome.org/GNOME/gnome-keyring/-/issues/5#note_1876550 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2018-19358 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-19358 | ||
| https://www.youtube.com/watch?v=Do4E9ZQaPck | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.