CVE-2020-14391: Medium severity gnome control center vulnerability
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.
Other sources
When registering a system through GNOME Control Center, Red Hat Customer Portal password gets sent to the system log and it is passed as an argument to gnome-settings-daemon helper, making it readable by an unprivileged local user.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-14391.
What is the severity of CVE-2020-14391?
The severity of CVE-2020-14391 is medium.
How does CVE-2020-14391 impact Red Hat Enterprise Linux 8?
CVE-2020-14391 allows a local attacker to discover Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface.
What software is affected by CVE-2020-14391?
The GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2 is affected by CVE-2020-14391.
How can I mitigate the vulnerability CVE-2020-14391?
Update to Red Hat Enterprise Linux 8.2 or later to fix the vulnerability CVE-2020-14391.