Back

HIGH

gnome-keyring: login credentials retrieval via a Secret Service API call

Published Nov 18, 2018

Description

GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML elements) are not used. NOTE: the vendor disputes this because, according to the security model, untrusted applications must not be allowed to access the user's session bus socket.

Affected products

Remediation

Red Hat statement

Red Hat has determined that this flaw is not a security vulnerability pertaining to gnome-keyring as the underlying issue is that there is currently no way (except by using Flatkpak, sandboxing, containers, etc.) to completely separate user applications from each other, which in turn means it is possible for applications running in the same user session to gain access to each other's secrets.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 18, 2018
Updated Sep 17, 2024
Reserved Nov 18, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 6, 2018