CVE-2018-17957

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
26/12/2018
Last modified:
07/11/2023

Description

The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, allowing local attackers to access or corrupt the RMT database.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:suse:repository_mirroring_tool:*:*:*:*:*:*:*:* 1.1.2 (excluding)