CVE-2022-45154
Summary
| CVE | CVE-2022-45154 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-15 10:15:00 UTC |
| Updated | 2023-02-24 18:58:00 UTC |
| Description | A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 15 SP3 allows attackers that get access to the support logs to gain knowledge of the stored credentials This issue affects: SUSE Linux Enterprise Server 12 supportutils version 3.0.10-95.51.1CWE-312: Cleartext Storage of Sensitive Information and prior versions. SUSE Linux Enterprise Server 15 supportutils version 3.1.21-150000.5.44.1 and prior versions. SUSE Linux Enterprise Server 15 SP3 supportutils version 3.1.21-150300.7.35.15.1 and prior versions. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Bug 1207598 – VUL-0: CVE-2022-45154: supportconfig: does not remove passwords in /etc/iscsi/iscsid.conf and /etc/target/lio_setup.sh |
CONFIRM |
bugzilla.suse.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Nozomi Matsuzawa
Legacy QID Mappings
- 754077 SUSE Enterprise Linux Security Update for supportutils (SUSE-SU-2023:2465-1)
- 754946 SUSE Enterprise Linux Security Update for supportutils (SUSE-SU-2023:3803-1)
- 754968 SUSE Enterprise Linux Security Update for supportutils (SUSE-SU-2023:3822-1)