Vulnerability Details CVE-2018-19358
GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML elements) are not used. NOTE: the vendor disputes this because, according to the security model, untrusted applications must not be allowed to access the user's session bus socket.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 27.4%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 2.1
Products affected by CVE-2018-19358
-
cpe:2.3:a:gnome:gnome-keyring:0.1.0
-
cpe:2.3:a:gnome:gnome-keyring:0.1.3
-
cpe:2.3:a:gnome:gnome-keyring:0.1.4
-
cpe:2.3:a:gnome:gnome-keyring:0.1.90
-
cpe:2.3:a:gnome:gnome-keyring:0.1.91
-
cpe:2.3:a:gnome:gnome-keyring:0.17.4
-
cpe:2.3:a:gnome:gnome-keyring:0.2.0
-
cpe:2.3:a:gnome:gnome-keyring:0.2.1
-
cpe:2.3:a:gnome:gnome-keyring:0.3.1
-
cpe:2.3:a:gnome:gnome-keyring:0.3.2
-
cpe:2.3:a:gnome:gnome-keyring:0.3.3
-
cpe:2.3:a:gnome:gnome-keyring:0.4.0
-
cpe:2.3:a:gnome:gnome-keyring:0.4.1
-
cpe:2.3:a:gnome:gnome-keyring:0.4.2
-
cpe:2.3:a:gnome:gnome-keyring:0.4.3
-
cpe:2.3:a:gnome:gnome-keyring:0.4.4
-
cpe:2.3:a:gnome:gnome-keyring:0.4.5
-
cpe:2.3:a:gnome:gnome-keyring:0.4.6
-
cpe:2.3:a:gnome:gnome-keyring:0.4.7
-
cpe:2.3:a:gnome:gnome-keyring:0.4.8
-
cpe:2.3:a:gnome:gnome-keyring:0.4.9
-
cpe:2.3:a:gnome:gnome-keyring:0.5.1
-
cpe:2.3:a:gnome:gnome-keyring:0.5.2
-
cpe:2.3:a:gnome:gnome-keyring:0.6.0
-
cpe:2.3:a:gnome:gnome-keyring:0.7.1
-
cpe:2.3:a:gnome:gnome-keyring:0.7.2
-
cpe:2.3:a:gnome:gnome-keyring:0.7.3
-
cpe:2.3:a:gnome:gnome-keyring:0.7.91
-
cpe:2.3:a:gnome:gnome-keyring:0.7.92
-
cpe:2.3:a:gnome:gnome-keyring:0.8
-
cpe:2.3:a:gnome:gnome-keyring:0.8.1
-
cpe:2.3:a:gnome:gnome-keyring:2.19.2
-
cpe:2.3:a:gnome:gnome-keyring:2.19.4
-
cpe:2.3:a:gnome:gnome-keyring:2.19.4.1
-
cpe:2.3:a:gnome:gnome-keyring:2.19.5
-
cpe:2.3:a:gnome:gnome-keyring:2.19.6
-
cpe:2.3:a:gnome:gnome-keyring:2.19.6.1
-
cpe:2.3:a:gnome:gnome-keyring:2.19.90
-
cpe:2.3:a:gnome:gnome-keyring:2.19.91
-
cpe:2.3:a:gnome:gnome-keyring:2.20.0
-
cpe:2.3:a:gnome:gnome-keyring:2.20.1
-
cpe:2.3:a:gnome:gnome-keyring:2.20.2
-
cpe:2.3:a:gnome:gnome-keyring:2.20.3
-
cpe:2.3:a:gnome:gnome-keyring:2.21.3
-
cpe:2.3:a:gnome:gnome-keyring:2.21.3.1
-
cpe:2.3:a:gnome:gnome-keyring:2.21.3.2
-
cpe:2.3:a:gnome:gnome-keyring:2.21.4
-
cpe:2.3:a:gnome:gnome-keyring:2.21.5
-
cpe:2.3:a:gnome:gnome-keyring:2.21.90
-
cpe:2.3:a:gnome:gnome-keyring:2.21.91
-
cpe:2.3:a:gnome:gnome-keyring:2.21.92
-
cpe:2.3:a:gnome:gnome-keyring:2.22.0
-
cpe:2.3:a:gnome:gnome-keyring:2.22.1
-
cpe:2.3:a:gnome:gnome-keyring:2.22.2
-
cpe:2.3:a:gnome:gnome-keyring:2.23.3
-
cpe:2.3:a:gnome:gnome-keyring:2.23.5
-
cpe:2.3:a:gnome:gnome-keyring:2.23.6
-
cpe:2.3:a:gnome:gnome-keyring:2.23.90
-
cpe:2.3:a:gnome:gnome-keyring:2.23.91
-
cpe:2.3:a:gnome:gnome-keyring:2.23.92
-
cpe:2.3:a:gnome:gnome-keyring:2.24.0
-
cpe:2.3:a:gnome:gnome-keyring:2.24.1
-
cpe:2.3:a:gnome:gnome-keyring:2.25.1
-
cpe:2.3:a:gnome:gnome-keyring:2.25.2
-
cpe:2.3:a:gnome:gnome-keyring:2.25.4
-
cpe:2.3:a:gnome:gnome-keyring:2.25.4.1
-
cpe:2.3:a:gnome:gnome-keyring:2.25.4.2
-
cpe:2.3:a:gnome:gnome-keyring:2.25.5
-
cpe:2.3:a:gnome:gnome-keyring:2.25.90
-
cpe:2.3:a:gnome:gnome-keyring:2.25.91
-
cpe:2.3:a:gnome:gnome-keyring:2.25.92
-
cpe:2.3:a:gnome:gnome-keyring:2.26.0
-
cpe:2.3:a:gnome:gnome-keyring:2.26.1
-
cpe:2.3:a:gnome:gnome-keyring:2.27.4
-
cpe:2.3:a:gnome:gnome-keyring:2.27.5
-
cpe:2.3:a:gnome:gnome-keyring:2.27.90
-
cpe:2.3:a:gnome:gnome-keyring:2.27.92
-
cpe:2.3:a:gnome:gnome-keyring:2.28.0
-
cpe:2.3:a:gnome:gnome-keyring:2.28.1
-
cpe:2.3:a:gnome:gnome-keyring:2.28.2
-
cpe:2.3:a:gnome:gnome-keyring:2.29.4
-
cpe:2.3:a:gnome:gnome-keyring:2.29.5
-
cpe:2.3:a:gnome:gnome-keyring:2.29.90
-
cpe:2.3:a:gnome:gnome-keyring:2.29.92
-
cpe:2.3:a:gnome:gnome-keyring:2.30.0
-
cpe:2.3:a:gnome:gnome-keyring:2.30.1
-
cpe:2.3:a:gnome:gnome-keyring:2.30.2
-
cpe:2.3:a:gnome:gnome-keyring:2.30.3
-
cpe:2.3:a:gnome:gnome-keyring:2.31.4
-
cpe:2.3:a:gnome:gnome-keyring:2.31.91
-
cpe:2.3:a:gnome:gnome-keyring:2.31.92
-
cpe:2.3:a:gnome:gnome-keyring:2.32.0
-
cpe:2.3:a:gnome:gnome-keyring:2.32.1
-
cpe:2.3:a:gnome:gnome-keyring:2.63.3
-
cpe:2.3:a:gnome:gnome-keyring:2.91.0
-
cpe:2.3:a:gnome:gnome-keyring:2.91.1
-
cpe:2.3:a:gnome:gnome-keyring:2.91.2
-
cpe:2.3:a:gnome:gnome-keyring:2.91.3
-
cpe:2.3:a:gnome:gnome-keyring:2.91.33
-
cpe:2.3:a:gnome:gnome-keyring:2.91.4
-
cpe:2.3:a:gnome:gnome-keyring:2.91.91
-
cpe:2.3:a:gnome:gnome-keyring:2.91.92
-
cpe:2.3:a:gnome:gnome-keyring:3.0.0
-
cpe:2.3:a:gnome:gnome-keyring:3.0.1
-
cpe:2.3:a:gnome:gnome-keyring:3.0.2
-
cpe:2.3:a:gnome:gnome-keyring:3.0.3
-
cpe:2.3:a:gnome:gnome-keyring:3.1.1
-
cpe:2.3:a:gnome:gnome-keyring:3.1.4
-
cpe:2.3:a:gnome:gnome-keyring:3.1.90
-
cpe:2.3:a:gnome:gnome-keyring:3.1.91
-
cpe:2.3:a:gnome:gnome-keyring:3.1.92
-
cpe:2.3:a:gnome:gnome-keyring:3.10.0
-
cpe:2.3:a:gnome:gnome-keyring:3.10.1
-
cpe:2.3:a:gnome:gnome-keyring:3.11.92
-
cpe:2.3:a:gnome:gnome-keyring:3.12.0
-
cpe:2.3:a:gnome:gnome-keyring:3.12.2
-
cpe:2.3:a:gnome:gnome-keyring:3.13.91
-
cpe:2.3:a:gnome:gnome-keyring:3.14.0
-
cpe:2.3:a:gnome:gnome-keyring:3.15.90
-
cpe:2.3:a:gnome:gnome-keyring:3.15.92
-
cpe:2.3:a:gnome:gnome-keyring:3.16.0
-
cpe:2.3:a:gnome:gnome-keyring:3.17.4
-
cpe:2.3:a:gnome:gnome-keyring:3.17.91
-
cpe:2.3:a:gnome:gnome-keyring:3.18.0
-
cpe:2.3:a:gnome:gnome-keyring:3.18.1
-
cpe:2.3:a:gnome:gnome-keyring:3.18.2
-
cpe:2.3:a:gnome:gnome-keyring:3.18.3
-
cpe:2.3:a:gnome:gnome-keyring:3.19.4
-
cpe:2.3:a:gnome:gnome-keyring:3.19.90
-
cpe:2.3:a:gnome:gnome-keyring:3.2.0
-
cpe:2.3:a:gnome:gnome-keyring:3.2.1
-
cpe:2.3:a:gnome:gnome-keyring:3.2.2
-
cpe:2.3:a:gnome:gnome-keyring:3.20.0
-
cpe:2.3:a:gnome:gnome-keyring:3.20.1
-
cpe:2.3:a:gnome:gnome-keyring:3.27.2
-
cpe:2.3:a:gnome:gnome-keyring:3.27.4
-
cpe:2.3:a:gnome:gnome-keyring:3.27.92
-
cpe:2.3:a:gnome:gnome-keyring:3.28.0
-
cpe:2.3:a:gnome:gnome-keyring:3.28.0.1
-
cpe:2.3:a:gnome:gnome-keyring:3.28.0.2
-
cpe:2.3:a:gnome:gnome-keyring:3.28.2
-
cpe:2.3:a:gnome:gnome-keyring:3.3.1
-
cpe:2.3:a:gnome:gnome-keyring:3.3.1.1
-
cpe:2.3:a:gnome:gnome-keyring:3.3.2
-
cpe:2.3:a:gnome:gnome-keyring:3.3.3
-
cpe:2.3:a:gnome:gnome-keyring:3.3.3.1
-
cpe:2.3:a:gnome:gnome-keyring:3.3.4
-
cpe:2.3:a:gnome:gnome-keyring:3.3.5
-
cpe:2.3:a:gnome:gnome-keyring:3.3.91
-
cpe:2.3:a:gnome:gnome-keyring:3.3.92
-
cpe:2.3:a:gnome:gnome-keyring:3.4.0
-
cpe:2.3:a:gnome:gnome-keyring:3.4.1
-
cpe:2.3:a:gnome:gnome-keyring:3.5.3
-
cpe:2.3:a:gnome:gnome-keyring:3.5.4
-
cpe:2.3:a:gnome:gnome-keyring:3.5.5
-
cpe:2.3:a:gnome:gnome-keyring:3.5.90
-
cpe:2.3:a:gnome:gnome-keyring:3.5.91
-
cpe:2.3:a:gnome:gnome-keyring:3.5.92
-
cpe:2.3:a:gnome:gnome-keyring:3.6.0
-
cpe:2.3:a:gnome:gnome-keyring:3.6.1
-
cpe:2.3:a:gnome:gnome-keyring:3.6.2
-
cpe:2.3:a:gnome:gnome-keyring:3.6.3
-
cpe:2.3:a:gnome:gnome-keyring:3.7.1
-
cpe:2.3:a:gnome:gnome-keyring:3.7.2
-
cpe:2.3:a:gnome:gnome-keyring:3.7.5
-
cpe:2.3:a:gnome:gnome-keyring:3.7.91
-
cpe:2.3:a:gnome:gnome-keyring:3.7.92
-
cpe:2.3:a:gnome:gnome-keyring:3.8.0
-
cpe:2.3:a:gnome:gnome-keyring:3.8.1
-
cpe:2.3:a:gnome:gnome-keyring:3.8.2
-
cpe:2.3:a:gnome:gnome-keyring:3.9.1
-
cpe:2.3:a:gnome:gnome-keyring:3.9.90