Subiquity
by Canonical
Source repositories
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-14551 | Hig | 0.46 | 8.1 | 0.00 | Apr 9, 2026 | In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the… | ||
| CVE-2022-0555 | Hig | 0.00 | 8.4 | 0.00 | Jun 3, 2024 | Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions | ||
| CVE-2023-5182 | Med | 0.00 | 5.5 | 0.00 | Oct 7, 2023 | Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find hashed passwords and possibly escalate their privilege. | ||
| CVE-2020-11932 | Low | 0.00 | 2.3 | 0.01 | May 13, 2020 | It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered. |
- risk 0.46cvss 8.1epss 0.00
In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the…
- risk 0.00cvss 8.4epss 0.00
Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions
- risk 0.00cvss 5.5epss 0.00
Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find hashed passwords and possibly escalate their privilege.
- risk 0.00cvss 2.3epss 0.01
It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.