First published: Thu Aug 27 2020(Updated: )
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME Control Center | ||
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux Aus | =8.2 | |
Redhat Enterprise Linux Eus | =8.2 | |
Redhat Enterprise Linux Tus | =8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-14391.
The severity of CVE-2020-14391 is medium.
CVE-2020-14391 allows a local attacker to discover Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface.
The GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2 is affected by CVE-2020-14391.
Update to Red Hat Enterprise Linux 8.2 or later to fix the vulnerability CVE-2020-14391.