← back
CVE-2018-20781

CVE-2018-20781

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 1.5%
from disclosure to weapon0 days
Published on NVDFeb 12
metasploitMay 23
exploitation probability
1.5%top 28% of all CVEs
observed exploitation
nono source reports it
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.
Affected products
n/a · n/a