Medium severity4.0NVD Advisory· Published Jan 27, 2020· Updated Jun 17, 2026
CVE-2018-20105
CVE-2018-20105
Description
A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11cpe:2.3:o:suse:suse_linux_enterprise_server:15:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:suse:suse_linux_enterprise_server:15:*:*:*:*:*:*:*
- (no CPE)range: yast2-rmt
- Range: <1.2.2
- osv-coords5 versionspkg:rpm/opensuse/yast2-rmt&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/yast2-rmt&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/yast2-rmt&distro=openSUSE%20Tumbleweedpkg:rpm/suse/yast2-rmt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015pkg:rpm/suse/yast2-rmt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1
< 1.2.2-lp150.2.19.1+ 4 more
- (no CPE)range: < 1.2.2-lp150.2.19.1
- (no CPE)range: < 1.2.2-lp151.2.3.1
- (no CPE)range: < 1.3.3-1.2
- (no CPE)range: < 1.2.2-3.18.1
- (no CPE)range: < 1.3.0-3.5.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.