CVE-2020-14391

EUVD-2020-6530
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
Affected Products (NVD)
VendorProductVersion
gnomecontrol_center
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gnome-settings-daemon
bookworm
43.0-4
fixed
bullseye
3.38.2-1
fixed
sid
47.1-2
fixed
trixie
47.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnome-settings-daemon
bionic
not-affected
focal
not-affected
trusty
dne
xenial
not-affected