yast2-rmt leaks database passwords in process list
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.4epss 0.4%
exploitation probability
0.4%top 69% of all CVEs
observed exploitation
nono source reports it
The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, allowing local attackers to access or corrupt the RMT database.
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Affected products
SUSE · yast2-rmt