CVE Vulnerabilities

CVE-2023-5182

Insertion of Sensitive Information into Log File

Published: Oct 07, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find hashed passwords and possibly escalate their privilege.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Subiquity Canonical * 23.09.1 (including)
Subiquity Ubuntu bionic *
Subiquity Ubuntu esm-apps/bionic *
Subiquity Ubuntu esm-apps/focal *
Subiquity Ubuntu esm-apps/jammy *
Subiquity Ubuntu focal *
Subiquity Ubuntu jammy *
Subiquity Ubuntu snap *
Subiquity Ubuntu trusty *
Subiquity Ubuntu upstream *
Subiquity Ubuntu xenial *

Potential Mitigations

References