vulnerability
Red Hat: CVE-2024-36472: gnome-shell: code execution in portal helper (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:A/AC:M/Au:N/C:C/I:C/A:C) | May 28, 2024 | Sep 13, 2024 | Sep 1, 2025 |
Severity
8
CVSS
(AV:A/AC:M/Au:N/C:C/I:C/A:C)
Published
May 28, 2024
Added
Sep 13, 2024
Modified
Sep 1, 2025
Description
In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior.
Solutions
no-fix-redhat-rpm-packageredhat-upgrade-gnome-classic-sessionredhat-upgrade-gnome-shellredhat-upgrade-gnome-shell-debuginforedhat-upgrade-gnome-shell-debugsourceredhat-upgrade-gnome-shell-extension-apps-menuredhat-upgrade-gnome-shell-extension-auto-move-windowsredhat-upgrade-gnome-shell-extension-classification-bannerredhat-upgrade-gnome-shell-extension-commonredhat-upgrade-gnome-shell-extension-custom-menuredhat-upgrade-gnome-shell-extension-dash-to-dockredhat-upgrade-gnome-shell-extension-dash-to-panelredhat-upgrade-gnome-shell-extension-desktop-iconsredhat-upgrade-gnome-shell-extension-drive-menuredhat-upgrade-gnome-shell-extension-gesture-inhibitorredhat-upgrade-gnome-shell-extension-heads-up-displayredhat-upgrade-gnome-shell-extension-launch-new-instanceredhat-upgrade-gnome-shell-extension-native-window-placementredhat-upgrade-gnome-shell-extension-panel-favoritesredhat-upgrade-gnome-shell-extension-places-menuredhat-upgrade-gnome-shell-extension-screenshot-window-sizerredhat-upgrade-gnome-shell-extension-systemmonitorredhat-upgrade-gnome-shell-extension-top-iconsredhat-upgrade-gnome-shell-extension-updates-dialogredhat-upgrade-gnome-shell-extension-user-themeredhat-upgrade-gnome-shell-extension-window-listredhat-upgrade-gnome-shell-extension-windowsnavigatorredhat-upgrade-gnome-shell-extension-workspace-indicator
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.