First published: Mon Jan 27 2020(Updated: )
A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Yast2-rmt Project Yast2-rmt | <1.2.2 | |
openSUSE Leap | =15.0 | |
SUSE SUSE Linux Enterprise Server | =15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20105 is a vulnerability that allows local attackers to learn the password if they can access the log file in yast2-rmt of SUSE Linux Enterprise Server 15 and openSUSE Leap.
CVE-2018-20105 has a severity rating of medium with a CVSS score of 5.5.
CVE-2018-20105 affects yast2-rmt versions prior to 1.2.2 in SUSE Linux Enterprise Server 15 and openSUSE Leap 15.0.
An attacker can exploit CVE-2018-20105 by accessing the log file to learn the password.
To fix CVE-2018-20105, update yast2-rmt to version 1.2.2 or later.