CVE detail
CVE-2018-20105 — CVE-2018-20105
Published 2020-01-27 · Modified 2026-06-17 · Vendor yast2-rmt_project · Product yast2-rmt · Source nvd
MEDIUM
severity
CVSS-derived band
0.0043
EPSS probability
exploitation probability, 30d
35.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References