Vulnerability Description
A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yast2-Rmt Project | Yast2-Rmt | < 1.2.2 |
| Opensuse | Leap | 15.0 |
| Suse | Suse Linux Enterprise Server | 15 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00035.html
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00015.html
- https://bugzilla.suse.com/show_bug.cgi?id=1119835
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00035.html
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00015.html
- https://bugzilla.suse.com/show_bug.cgi?id=1119835
FAQ
What is CVE-2018-20105?
CVE-2018-20105 is a vulnerability with a CVSS score of 4.0 (MEDIUM). A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log f...
How severe is CVE-2018-20105?
CVE-2018-20105 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20105?
Check the references section above for vendor advisories and patch information. Affected products include: Yast2-Rmt Project Yast2-Rmt, Opensuse Leap, Suse Suse Linux Enterprise Server.