CVE Database
/

CVE-2020-27837

Back to search

CVE-2020-27837

Published: Dec 28, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

A flaw was found in GDM in versions prior to 3.38.2.1. A race condition in the handling of session shutdown makes it possible to bypass the lock screen for a user that has autologin enabled, accessing their session without authentication. This is similar to CVE-2017-12164, but requires more difficult conditions to exploit.

VendorProductVersions

n/a

gdm

affected
prior to 3.38.2.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now