CVE Vulnerabilities

CVE-2020-14391

Insufficiently Protected Credentials

Published: Feb 08, 2021 | Modified: Feb 12, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Ubuntu

A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Control_center Gnome - (including) - (including)
Red Hat Enterprise Linux 8 RedHat gnome-settings-daemon-0:3.32.0-11.el8 *
Red Hat Enterprise Linux 8.2 Extended Update Support RedHat gnome-settings-daemon-0:3.32.0-9.el8_2.1 *

Potential Mitigations

References