CVE Vulnerabilities

CVE-2023-5182

Insertion of Sensitive Information into Log File

Published: Oct 07, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find hashed passwords and possibly escalate their privilege.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
SubiquityCanonical*23.09.1 (including)
SubiquityUbuntubionic*
SubiquityUbuntuesm-apps/bionic*
SubiquityUbuntuesm-apps/focal*
SubiquityUbuntuesm-apps/jammy*
SubiquityUbuntufocal*
SubiquityUbuntujammy*
SubiquityUbuntusnap*
SubiquityUbuntutrusty*
SubiquityUbuntuupstream*
SubiquityUbuntuxenial*

Potential Mitigations

References