CVE-2022-0555
Published Jun 3, 2024Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions
Vendor/product archive
3 CVEs tagged to canonical / subiquity — 0 Critical, 1 High, 1 Medium, 1 Low, 0 Unrated.
Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions
Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find hashed passwords and possibly esc…
It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.