CVE-2019-13313: Fedoraproject Fedora

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.

Affected products

  • Fedoraproject Fedora: version 29 only; version 30 only
  • Libosinfo Libosinfo: version 1.5.0 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Eus: version 8.1 only; version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only; version 8.6 only

Published 2019-07-05. Last modified 2026-06-17.