Password visible at login screen

Bug #1779637 reported by Chris Burgess
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gnome-screensaver (Ubuntu)
New
High
Unassigned
gnome-shell (Ubuntu)
New
High
Unassigned

Bug Description

We have a shared computer (2 user accounts) and I was surprised to find after screen lock that my password was visible when entering it to log back in.

* Ubuntu 18.04 LTS / 18.04
* gdm 3.28.2-0ubuntu1.2 (I don't seem to have any packages matching screensaver, so GDM?)

I expected: to see masked characters when entering my password

I saw: my password visible on screen!

I was not able to repeat the issue after a reboot.

Checking "security" because that way security team gets to decide if this is really a vulnerability - sorry if that's turning the volume up a bit high, I won't be offended if you make it public straight away, but I'd rather you had the option than that I got it wrong.

Revision history for this message
Chris Burgess (chris-giantrobot) wrote :
Emily Ratliff (emilyr)
information type: Private Security → Public Security
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in gnome-screensaver (Ubuntu):
status: New → Confirmed
Revision history for this message
Daniel van Vugt (vanvugt) wrote :

The lock GUI is provided by 'gnome-shell'

Changed in gnome-screensaver (Ubuntu):
importance: Undecided → High
Changed in gnome-shell (Ubuntu):
importance: Undecided → High
Changed in gnome-screensaver (Ubuntu):
status: Confirmed → New
Revision history for this message
Daniel van Vugt (vanvugt) wrote :

Thank you for taking the time to report this bug and helping to make Ubuntu better. This particular bug has already been reported and is a duplicate of bug 1772791, so it is being marked as such. Please look at the other bug report to see if there is any missing information that you can provide, or to see if there is a workaround for the bug. Additionally, any further discussion regarding the bug should occur in the other report. Feel free to continue to report any other bugs you may find.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.