Upstream information

CVE-2020-14391 at MITRE

Description

A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
CVSS detail National Vulnerability Database
Base Score 2.1
Vector AV:L/AC:L/Au:N/C:P/I:N/A:N
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
CVSS v3 Scores
CVSS detail National Vulnerability Database
Base Score 5.5
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Impact High
Integrity Impact None
Availability Impact None
CVSSv3 Version 3.1
No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Liberty Linux 8
  • LibRaw >= 0.19.5-2.el8
  • PackageKit >= 1.1.12-6.el8
  • PackageKit-command-not-found >= 1.1.12-6.el8
  • PackageKit-cron >= 1.1.12-6.el8
  • PackageKit-glib >= 1.1.12-6.el8
  • PackageKit-gstreamer-plugin >= 1.1.12-6.el8
  • PackageKit-gtk3-module >= 1.1.12-6.el8
  • dleyna-renderer >= 0.6.0-3.el8
  • frei0r-plugins >= 1.6.1-7.el8
  • frei0r-plugins-opencv >= 1.6.1-7.el8
  • gdm >= 3.28.3-34.el8
  • gnome-classic-session >= 3.32.1-11.el8
  • gnome-control-center >= 3.28.2-22.el8
  • gnome-control-center-filesystem >= 3.28.2-22.el8
  • gnome-photos >= 3.28.1-3.el8
  • gnome-photos-tests >= 3.28.1-3.el8
  • gnome-remote-desktop >= 0.1.8-3.el8
  • gnome-session >= 3.28.1-10.el8
  • gnome-session-wayland-session >= 3.28.1-10.el8
  • gnome-session-xsession >= 3.28.1-10.el8
  • gnome-settings-daemon >= 3.32.0-11.el8
  • gnome-shell >= 3.32.2-20.el8
  • gnome-shell-extension-apps-menu >= 3.32.1-11.el8
  • gnome-shell-extension-auto-move-windows >= 3.32.1-11.el8
  • gnome-shell-extension-common >= 3.32.1-11.el8
  • gnome-shell-extension-dash-to-dock >= 3.32.1-11.el8
  • gnome-shell-extension-desktop-icons >= 3.32.1-11.el8
  • gnome-shell-extension-disable-screenshield >= 3.32.1-11.el8
  • gnome-shell-extension-drive-menu >= 3.32.1-11.el8
  • gnome-shell-extension-horizontal-workspaces >= 3.32.1-11.el8
  • gnome-shell-extension-launch-new-instance >= 3.32.1-11.el8
  • gnome-shell-extension-native-window-placement >= 3.32.1-11.el8
  • gnome-shell-extension-no-hot-corner >= 3.32.1-11.el8
  • gnome-shell-extension-panel-favorites >= 3.32.1-11.el8
  • gnome-shell-extension-places-menu >= 3.32.1-11.el8
  • gnome-shell-extension-screenshot-window-sizer >= 3.32.1-11.el8
  • gnome-shell-extension-systemMonitor >= 3.32.1-11.el8
  • gnome-shell-extension-top-icons >= 3.32.1-11.el8
  • gnome-shell-extension-updates-dialog >= 3.32.1-11.el8
  • gnome-shell-extension-user-theme >= 3.32.1-11.el8
  • gnome-shell-extension-window-grouper >= 3.32.1-11.el8
  • gnome-shell-extension-window-list >= 3.32.1-11.el8
  • gnome-shell-extension-windowsNavigator >= 3.32.1-11.el8
  • gnome-shell-extension-workspace-indicator >= 3.32.1-11.el8
  • gnome-terminal >= 3.28.3-2.el8
  • gnome-terminal-nautilus >= 3.28.3-2.el8
  • gsettings-desktop-schemas >= 3.32.0-5.el8
  • gsettings-desktop-schemas-devel >= 3.32.0-5.el8
  • gtk-update-icon-cache >= 3.22.30-6.el8
  • gtk3 >= 3.22.30-6.el8
  • gtk3-devel >= 3.22.30-6.el8
  • gtk3-immodule-xim >= 3.22.30-6.el8
  • gvfs >= 1.36.2-10.el8
  • gvfs-afc >= 1.36.2-10.el8
  • gvfs-afp >= 1.36.2-10.el8
  • gvfs-archive >= 1.36.2-10.el8
  • gvfs-client >= 1.36.2-10.el8
  • gvfs-devel >= 1.36.2-10.el8
  • gvfs-fuse >= 1.36.2-10.el8
  • gvfs-goa >= 1.36.2-10.el8
  • gvfs-gphoto2 >= 1.36.2-10.el8
  • gvfs-mtp >= 1.36.2-10.el8
  • gvfs-smb >= 1.36.2-10.el8
  • libsoup >= 2.62.3-2.el8
  • libsoup-devel >= 2.62.3-2.el8
  • mutter >= 3.32.2-48.el8
  • nautilus >= 3.28.1-14.el8
  • nautilus-extensions >= 3.28.1-14.el8
  • pipewire >= 0.3.6-1.el8
  • pipewire-devel >= 0.3.6-1.el8
  • pipewire-doc >= 0.3.6-1.el8
  • pipewire-libs >= 0.3.6-1.el8
  • pipewire-utils >= 0.3.6-1.el8
  • pipewire0.2-devel >= 0.2.7-6.el8
  • pipewire0.2-libs >= 0.2.7-6.el8
  • potrace >= 1.15-3.el8
  • python3-gobject >= 3.28.3-2.el8
  • python3-gobject-base >= 3.28.3-2.el8
  • tracker >= 2.1.5-2.el8
  • vte-profile >= 0.52.4-2.el8
  • vte291 >= 0.52.4-2.el8
  • webkit2gtk3 >= 2.28.4-1.el8
  • webkit2gtk3-devel >= 2.28.4-1.el8
  • webkit2gtk3-jsc >= 2.28.4-1.el8
  • webkit2gtk3-jsc-devel >= 2.28.4-1.el8
  • webrtc-audio-processing >= 0.3-9.el8
  • xdg-desktop-portal >= 1.6.0-2.el8
  • xdg-desktop-portal-gtk >= 1.6.0-1.el8
Patchnames:
RHSA-2020:4451


SUSE Timeline for this CVE

CVE page created: Tue Sep 8 17:19:11 2020
CVE page last modified: Fri Mar 27 17:52:11 2026