CVE Vulnerabilities

CVE-2025-6224

Cleartext Storage of Sensitive Information

Published: Jul 01, 2025 | Modified: Sep 10, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and trivially extract the private key from it.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Juju/utils Canonical 4.0.0 (including) 4.0.4 (excluding)
Golang-github-juju-utils Ubuntu oracular *

Potential Mitigations

References