CVE-2022-45154: supportconfig does not remove passwords in /etc/iscsi/iscsid.conf and /etc/target/lio_setup.sh
A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 15 SP3 allows attackers that get access to the support logs to gain knowledge of the stored credentials This issue affects: SUSE Linux Enterprise Server 12 supportutils version 3.0.10-95.51.1CWE-312: Cleartext Storage of Sensitive Information and prior versions. SUSE Linux Enterprise Server 15 supportutils version 3.1.21-150000.5.44.1 and prior versions. SUSE Linux Enterprise Server 15 SP3 supportutils version 3.1.21-150300.7.35.15.1 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-45154?
CVE-2022-45154 is a Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 15 SP3.
How does CVE-2022-45154 affect Opensuse Supportutils?
CVE-2022-45154 affects Opensuse Supportutils versions 3.0.10-95.51.1 and 3.1.21-150000.5.44.1.
How does CVE-2022-45154 affect SUSE Linux Enterprise Server 12?
CVE-2022-45154 does not affect SUSE Linux Enterprise Server 12.
How does CVE-2022-45154 affect SUSE Linux Enterprise Server 15?
CVE-2022-45154 does not affect SUSE Linux Enterprise Server 15.
How does CVE-2022-45154 affect SUSE Linux Enterprise Server 15 SP3?
CVE-2022-45154 does not affect SUSE Linux Enterprise Server 15 SP3.
What is the severity of CVE-2022-45154?
The severity of CVE-2022-45154 is medium with a CVSS score of 5.5.
How can I fix CVE-2022-45154?
To fix CVE-2022-45154, it is recommended to update to a non-vulnerable version of suppportutils.
Where can I find more information about CVE-2022-45154?
You can find more information about CVE-2022-45154 at the following link: https://bugzilla.suse.com/show_bug.cgi?id=1207598
What is the CWE of CVE-2022-45154?
The CWE of CVE-2022-45154 is CWE-312: Cleartext Storage of Sensitive Information.