suse · CVE-2018-20105

Quick triage

Priority: medium Published: 2021-05-30 14:19:23 UTC Updated: 2025-08-14 02:22:20 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-20105 severity moderate: SUSE including 9 source package names (yast2-rmt, yast2-rmt-1.2.2-3.18.1, …), 11 product×package rows across 9 product lines (SUSE Linux Enterprise Module for Server Applications 15, SUSE Linux Enterprise Module for Server Applications 15 SP1, … (9 product lines)): Fixed 9, Known Not Affected 2.

Description:

A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.

cvelogic Threat Intelligence