CVE-2018-20105: Opensuse Leap
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt versions prior to 1.2.2.
Affected products
- Opensuse Leap: version 15.0 only
- Suse Suse Linux Enterprise Server: version 15 only
- YAST2-Rmt Project YAST2-Rmt: before 1.2.2 (fixed in 1.2.2)
Published 2020-01-27. Last modified 2026-06-17.