In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the attached logs.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 09 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the attached logs. | |
| Title | Senstive information disclosure was affecting subiquity | |
| Weaknesses | CWE-1258 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-04-09T15:03:58.798Z
Reserved: 2025-12-11T20:32:58.130Z
Link: CVE-2025-14551
No data.
Status : Received
Published: 2026-04-09T16:16:23.890
Modified: 2026-04-09T16:16:23.890
Link: CVE-2025-14551
No data.
OpenCVE Enrichment
No data.
Weaknesses