CVE-2020-14391 PUBLISHED

Reported by redhat · Published February 8, 2021

A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.

Affected Products

VendorProductVersions
n/agnome-settings-daemonRed Hat Enterprise Linux 8 versions prior to 8.2
n/agnome-settings-daemonRed Hat Enterprise Linux 8 versions prior to 8.2

Timeline

References

Open in Interactive Console →