Upstream information
CVE-2020-14391 at MITRE
Description
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
CVSS v2 Scores
| CVSS detail | National Vulnerability Database |
| Base Score | 2.1 |
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
| Access Vector | Local |
| Access Complexity | Low |
| Authentication | None |
| Confidentiality Impact | Partial |
| Integrity Impact | None |
| Availability Impact | None |
CVSS v3 Scores
| CVSS detail | National Vulnerability Database |
| Base Score | 5.5 |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| Attack Vector | Local |
| Attack Complexity | Low |
| Privileges Required | Low |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality Impact | High |
| Integrity Impact | None |
| Availability Impact | None |
| CVSSv3 Version | 3.1 |
No SUSE Bugzilla entries cross referenced.
No SUSE Security Announcements cross referenced.
List of released packages
| Product(s) | Fixed package version(s) | References |
| SUSE Liberty Linux 8 | LibRaw >= 0.19.5-2.el8
PackageKit >= 1.1.12-6.el8
PackageKit-command-not-found >= 1.1.12-6.el8
PackageKit-cron >= 1.1.12-6.el8
PackageKit-glib >= 1.1.12-6.el8
PackageKit-gstreamer-plugin >= 1.1.12-6.el8
PackageKit-gtk3-module >= 1.1.12-6.el8
dleyna-renderer >= 0.6.0-3.el8
frei0r-plugins >= 1.6.1-7.el8
frei0r-plugins-opencv >= 1.6.1-7.el8
gdm >= 3.28.3-34.el8
gnome-classic-session >= 3.32.1-11.el8
gnome-control-center >= 3.28.2-22.el8
gnome-control-center-filesystem >= 3.28.2-22.el8
gnome-photos >= 3.28.1-3.el8
gnome-photos-tests >= 3.28.1-3.el8
gnome-remote-desktop >= 0.1.8-3.el8
gnome-session >= 3.28.1-10.el8
gnome-session-wayland-session >= 3.28.1-10.el8
gnome-session-xsession >= 3.28.1-10.el8
gnome-settings-daemon >= 3.32.0-11.el8
gnome-shell >= 3.32.2-20.el8
gnome-shell-extension-apps-menu >= 3.32.1-11.el8
gnome-shell-extension-auto-move-windows >= 3.32.1-11.el8
gnome-shell-extension-common >= 3.32.1-11.el8
gnome-shell-extension-dash-to-dock >= 3.32.1-11.el8
gnome-shell-extension-desktop-icons >= 3.32.1-11.el8
gnome-shell-extension-disable-screenshield >= 3.32.1-11.el8
gnome-shell-extension-drive-menu >= 3.32.1-11.el8
gnome-shell-extension-horizontal-workspaces >= 3.32.1-11.el8
gnome-shell-extension-launch-new-instance >= 3.32.1-11.el8
gnome-shell-extension-native-window-placement >= 3.32.1-11.el8
gnome-shell-extension-no-hot-corner >= 3.32.1-11.el8
gnome-shell-extension-panel-favorites >= 3.32.1-11.el8
gnome-shell-extension-places-menu >= 3.32.1-11.el8
gnome-shell-extension-screenshot-window-sizer >= 3.32.1-11.el8
gnome-shell-extension-systemMonitor >= 3.32.1-11.el8
gnome-shell-extension-top-icons >= 3.32.1-11.el8
gnome-shell-extension-updates-dialog >= 3.32.1-11.el8
gnome-shell-extension-user-theme >= 3.32.1-11.el8
gnome-shell-extension-window-grouper >= 3.32.1-11.el8
gnome-shell-extension-window-list >= 3.32.1-11.el8
gnome-shell-extension-windowsNavigator >= 3.32.1-11.el8
gnome-shell-extension-workspace-indicator >= 3.32.1-11.el8
gnome-terminal >= 3.28.3-2.el8
gnome-terminal-nautilus >= 3.28.3-2.el8
gsettings-desktop-schemas >= 3.32.0-5.el8
gsettings-desktop-schemas-devel >= 3.32.0-5.el8
gtk-update-icon-cache >= 3.22.30-6.el8
gtk3 >= 3.22.30-6.el8
gtk3-devel >= 3.22.30-6.el8
gtk3-immodule-xim >= 3.22.30-6.el8
gvfs >= 1.36.2-10.el8
gvfs-afc >= 1.36.2-10.el8
gvfs-afp >= 1.36.2-10.el8
gvfs-archive >= 1.36.2-10.el8
gvfs-client >= 1.36.2-10.el8
gvfs-devel >= 1.36.2-10.el8
gvfs-fuse >= 1.36.2-10.el8
gvfs-goa >= 1.36.2-10.el8
gvfs-gphoto2 >= 1.36.2-10.el8
gvfs-mtp >= 1.36.2-10.el8
gvfs-smb >= 1.36.2-10.el8
libsoup >= 2.62.3-2.el8
libsoup-devel >= 2.62.3-2.el8
mutter >= 3.32.2-48.el8
nautilus >= 3.28.1-14.el8
nautilus-extensions >= 3.28.1-14.el8
pipewire >= 0.3.6-1.el8
pipewire-devel >= 0.3.6-1.el8
pipewire-doc >= 0.3.6-1.el8
pipewire-libs >= 0.3.6-1.el8
pipewire-utils >= 0.3.6-1.el8
pipewire0.2-devel >= 0.2.7-6.el8
pipewire0.2-libs >= 0.2.7-6.el8
potrace >= 1.15-3.el8
python3-gobject >= 3.28.3-2.el8
python3-gobject-base >= 3.28.3-2.el8
tracker >= 2.1.5-2.el8
vte-profile >= 0.52.4-2.el8
vte291 >= 0.52.4-2.el8
webkit2gtk3 >= 2.28.4-1.el8
webkit2gtk3-devel >= 2.28.4-1.el8
webkit2gtk3-jsc >= 2.28.4-1.el8
webkit2gtk3-jsc-devel >= 2.28.4-1.el8
webrtc-audio-processing >= 0.3-9.el8
xdg-desktop-portal >= 1.6.0-2.el8
xdg-desktop-portal-gtk >= 1.6.0-1.el8
| Patchnames: RHSA-2020:4451 |
SUSE Timeline for this CVE
CVE page created: Tue Sep 8 17:19:11 2020
CVE page last modified: Fri Mar 27 17:52:11 2026