yast2-rmt exposes CA private key passhrase in log-file
Vulnerability Description
A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-20105
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Fabian Schilling of SUSE
References
More from SUSE
View All →Affected Vendor
SUSE
View all reports →