Medium severity6.5NVD Advisory· Published Jul 1, 2025· Updated Jun 17, 2026
CVE-2025-6224
CVE-2025-6224
Description
Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and trivially extract the private key from it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/juju/utils/v4/certGo | < 4.0.4 | 4.0.4 |
Affected products
4cpe:2.3:a:canonical:juju\/utils:*:*:*:*:*:go:*:*+ 1 more
- cpe:2.3:a:canonical:juju\/utils:*:*:*:*:*:go:*:*range: >=4.0.0,<4.0.4
- (no CPE)range: 4.0.1
- ghsa-coords2 versionspkg:golang/github.com/juju/utils/v4/certpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Tumbleweed
< 4.0.4+ 1 more
- (no CPE)range: < 4.0.4
- (no CPE)range: < 0.0.20250730T213748-1.1
Patches
Vulnerability mechanics
References
5- github.com/juju/utils/security/advisories/GHSA-h34r-jxqm-qgprnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-h34r-jxqm-qgprghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-6224ghsaADVISORY
- github.com/juju/utils/commit/766f27d7bcd10433453a9764509a864c17a46a76ghsaWEB
- github.com/juju/utils/releases/tag/v4.0.4ghsaWEB
News mentions
0No linked articles in our index yet.