The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.CreditsMario BiberhoferReferenceshttps://www.suse.com/de-de/security/cve/CVE-2017-9271/https://bugzilla.suse.com/show_bug.cgi?id=1050625https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VP2DNHXEQFHXBCTSREPNR7BU4EX64SQG/