CVE Vulnerabilities

CVE-2020-11932

Insertion of Sensitive Information into Log File

Published: May 13, 2020 | Modified: Nov 21, 2024
CVSS 3.x
2.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
SubiquityCanonical*20.05.2 (excluding)
SubiquityUbuntubionic*
SubiquityUbuntueoan*
SubiquityUbuntuesm-apps/bionic*
SubiquityUbuntuesm-apps/focal*
SubiquityUbuntuesm-apps/jammy*
SubiquityUbuntufocal*
SubiquityUbuntugroovy*
SubiquityUbuntuhirsute*
SubiquityUbuntuimpish*
SubiquityUbuntujammy*
SubiquityUbuntukinetic*
SubiquityUbuntusnap*
SubiquityUbuntutrusty*
SubiquityUbuntuupstream*

Potential Mitigations

References