CVE-2020-11932

LOW

Canonical Subiquity < 20.05.2 - Log Information Exposure

Title source: rule
STIX 2.1

Description

It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.

Exploits (3)

nomisec WORKING POC 98 stars
by ProjectorBUg · poc
https://github.com/ProjectorBUg/CVE-2020-11932
nomisec SCANNER 3 stars
by Staubgeborener · poc
https://github.com/Staubgeborener/CVE-2020-11932
nomisec WORKING POC 1 stars
by code-developers · poc
https://github.com/code-developers/CVE-2020-11932

References (2)

Core 2

Scores

CVSS v3 2.3
EPSS 0.0171
EPSS Percentile 82.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-532
Status published
Products (1)
canonical/subiquity < 20.05.2
Published May 13, 2020
Tracked Since Feb 18, 2026