CVE-2018-17957

The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, allowing local attackers to access or corrupt the RMT database.
Configurations

Configuration 1 (hide)

cpe:2.3:a:suse:repository_mirroring_tool:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:55

Type Values Removed Values Added
CVSS v2 : 2.1
v3 : 7.8
v2 : 2.1
v3 : 3.4
References () https://bugzilla.suse.com/show_bug.cgi?id=1117602 - () https://bugzilla.suse.com/show_bug.cgi?id=1117602 -
References () https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00068.html - () https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00068.html -

07 Nov 2023, 02:54

Type Values Removed Values Added
References (CONFIRM) https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00068.html - Patch, Third Party Advisory () https://lists.opensuse.org/opensuse-security-announce/2018-12/msg00068.html -
References (CONFIRM) https://bugzilla.suse.com/show_bug.cgi?id=1117602 - Exploit, Issue Tracking, Third Party Advisory () https://bugzilla.suse.com/show_bug.cgi?id=1117602 -

Information

Published : 2018-12-26 15:29

Updated : 2024-11-21 03:55


NVD link : CVE-2018-17957

Mitre link : CVE-2018-17957

CVE.ORG link : CVE-2018-17957


JSON object : View

Products Affected

suse

  • repository_mirroring_tool
CWE
CWE-214

Invocation of Process Using Visible Sensitive Information

CWE-287

Improper Authentication