Back

HIGH

Libosinfo: osinfo-install-script option leaks password via command line argument

Published Jul 5, 2019

Description

libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.

Affected products

Remediation

No remediation recorded yet.

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 5, 2019
Updated Aug 4, 2024
Reserved Jul 5, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jul 5, 2019
ENISA EUVD
Assigner mitre
Published Jul 5, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-4818