Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

The-Magician

#37695of 53,632
7.5Total CVSS
Vulnerabilities · 1
PT-2020-13746
7.5
2020-06-06
Unknown · Pam Tacplus · CVE-2020-13881
**Name of the Vulnerable Software and Affected Versions** pam tacplus versions 1.3.8 through 1.5.1 **Description** The issue concerns the logging of the TACACS+ shared secret via syslog when the DEBUG loglevel and journald are used. This occurs in the support.c file of pam tacplus. **Recommendations** For pam tacplus versions 1.3.8 through 1.5.1, consider disabling the DEBUG loglevel or journald to prevent the TACACS+ shared secret from being logged via syslog until a patch is available.