CVE-2020-11932: Subiquity server installer logged LUKS full disk encryption password
It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-11932?
CVE-2020-11932 is a vulnerability discovered in the Subiquity installer for Ubuntu Server that logged the LUKS full disk encryption password if one was entered.
How severe is CVE-2020-11932?
CVE-2020-11932 has a severity rating of low.
What software is affected by CVE-2020-11932?
The Subiquity installer for Ubuntu Server version up to exclusive 20.05.2 is affected by CVE-2020-11932.
How can I fix CVE-2020-11932?
Upgrade to a version of Subiquity installer for Ubuntu Server that includes the fix for CVE-2020-11932.
Where can I find more information about CVE-2020-11932?
More information about CVE-2020-11932 can be found at the following references: [Link 1](https://aliceandbob.company/the-human-factor-in-an-economy-of-scale/), [Link 2](https://github.com/CanonicalLtd/subiquity/commit/7db70650feaf513d7fb6f1ca07f2d670a0890613).