CVE-2022-0555

HIGH

Subiquity < 22.02.1 - Plaintext Storage of a Password

Title source: llm
STIX 2.1

Description

Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions

References (4)

Core 4
Core References
Third Party Advisory issue-tracking
https://www.cve.org/CVERecord?id=CVE-2022-0555
Issue Tracking, Patch issue-tracking
https://github.com/canonical/subiquity/pull/1181
Issue Tracking, Patch issue-tracking
https://github.com/canonical/subiquity/pull/1182
Exploit, Issue Tracking issue-tracking
https://bugs.launchpad.net/subiquity/+bug/1960162

Scores

CVSS v3 8.4
EPSS 0.0028
EPSS Percentile 19.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-256
Status published
Products (1)
canonical/subiquity < 22.02.1
Published Jun 03, 2024
Tracked Since Feb 18, 2026