CVE-2024-5148

Source
https://cve.org/CVERecord?id=CVE-2024-5148
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5148.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-5148
Downstream
Related
Published
2024-09-02T11:03:18.235Z
Modified
2026-07-15T01:49:09.903026606Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Gnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificate
Details

A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the user session. As a result, the system RDP TLS certificate and key can be exposed to unauthorized users. This flaw allows a malicious user on the system to take control of the RDP client connection during the login screen-to-user session transition.

Database specific
{
    "cwe_ids": [
        "CWE-488"
    ],
    "cna_assigner": "redhat",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/5xxx/CVE-2024-5148.json"
}
References

Affected packages

Git / github.com/gnome/gnome-remote-desktop

Affected ranges

Type
GIT
Repo
https://github.com/gnome/gnome-remote-desktop
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "46.alpha"
        },
        {
            "fixed": "46.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

46.*
46.0
46.1
46.alpha
46.beta
46.rc

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-5148.json"