CVE-2018-20105

MEDIUM

yast2-rmt <1.2.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.

References (3)

Core 3
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.suse.com/show_bug.cgi?id=1119835

Scores

CVSS v3 4.0
EPSS 0.0014
EPSS Percentile 34.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-532
Status published
Products (3)
opensuse/leap 15.0
suse/suse_linux_enterprise_server 15
yast2-rmt_project/yast2-rmt < 1.2.2
Published Jan 27, 2020
Tracked Since Feb 18, 2026