Description
In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2239-1 | libpam-tacplus security update |
Debian DLA |
DLA-2730-1 | libpam-tacplus security update |
EUVD |
EUVD-2020-6089 | In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used. |
Ubuntu USN |
USN-4521-1 | pam_tacplus vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:32:14.180Z
Reserved: 2020-06-06T00:00:00.000Z
Link: CVE-2020-13881
No data.
Status : Modified
Published: 2020-06-06T19:15:09.610
Modified: 2026-06-17T02:53:49.723
Link: CVE-2020-13881
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-532
Insertion of Sensitive Information into Log File
Debian DLA
EUVD
Ubuntu USN