Описание
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.
A flaw was found in the GNOME Control Center, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.
Отчет
This issue did not affect the versions of gnome-settings-daemon as shipped with Red Hat Enterprise Linux 6, and 7 as they did not include the subscription-manager plugin.
Меры по смягчению последствий
Use subscription-manager
directly from the terminal and do not use the --password
flag.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | gnome-settings-daemon | Not affected | ||
Red Hat Enterprise Linux 7 | gnome-settings-daemon | Not affected | ||
Red Hat Enterprise Linux 8 | gnome-settings-daemon | Fixed | RHSA-2020:4451 | 04.11.2020 |
Red Hat Enterprise Linux 8.2 Extended Update Support | gnome-settings-daemon | Fixed | RHSA-2021:0266 | 26.01.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS3
Связанные уязвимости
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.
A flaw was found in the GNOME Control Center in Red Hat Enterprise Lin ...
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.
ELSA-2020-4451: GNOME security, bug fix, and enhancement update (MODERATE)
EPSS
5 Medium
CVSS3