CVE-2025-14551
LOW
2,7
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the attached logs.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0004
Percentile
0,1th
Updated
EPSS Score Trend (Last 7 Days)
1258
Exposure of Sensitive System Information Due to Uncleared Debug Information
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Access Control
Potential Impacts:
Read Memory
Bypass Protection Mechanism
Applicable Platforms
All platforms may be affected
https://github.com/canonical/subiquity/pull/2357
https://github.com/canonical/subiquity/pull/2358