VDB

CVE-2020-14391

CVE-2020-14391 PUBLISHED

Reported by redhat · Published February 8, 2021

A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.

Affected Products

VendorProductVersions
n/agnome-settings-daemonRed Hat Enterprise Linux 8 versions prior to 8.2
n/agnome-settings-daemon*

Timeline

  • Nov 4, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Oct 27, 2021 EPSS Score
  • Dec 29, 2021 EPSS Score
  • Mar 2, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 4, 2022 EPSS Score
  • Jul 6, 2022 EPSS Score
  • Sep 8, 2022 EPSS Score
  • Nov 10, 2022 EPSS Score

References

  • x_refsource_MISC
Open in Interactive Console →
$ Console Community · 100/wk Open console ›