Disable GUI inspection tool in secure mode#13487
Merged
Merged
Conversation
Contributor
|
The advisory will be published after the patch release is published. |
feerrenrut
previously approved these changes
Mar 16, 2022
See test results for failed build of commit 626741ed0e |
GitHub Advisory GHSA-mvc8-5rv9-w3hx Summary: The wx GUI inspection tool includes a python console. If the user binds a gesture to the startWxInspectionTool script and their config is copied to be used on logon screen, this tool could then be opened from the logon screen. This would allow a user to open the python console from the logon screen with system privileges. Description of change: Disables opening the wx GUI inspection tool when NVDA is running in secure mode.
5599960 to
196a791
Compare
5 tasks
8 tasks
5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Thanks to @CyrilleB79 for reporting.
Link to issue number:
GitHub Advisory GHSA-mvc8-5rv9-w3hx: GHSA-mvc8-5rv9-w3hx
Summary of the issue:
The wx GUI inspection tool includes a python console.
If the user binds a gesture to the startWxInspectionTool script and their config is copied to be used on logon screen, this tool can be opened from the logon screen.
This allows a user to open the python console from the logon screen with system privileges.
Description of how this pull request fixes the issue:
Disable the possibility to open wx GUI inspection tool when NVDA is running in secure mode.
Testing strategy:
Manual test:
Known issues with pull request:
None
Change log entries:
Security fixes
The wx GUI inspection tool is now disabled on secure screens.Code Review Checklist: