CVE-2023-5182: Medium severity subiquity vulnerability
Published Oct 6, 2023
·Updated
Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find hashed passwords and possibly escalate their privilege.
Affected Software
1 affected component
Canonical Subiquity<=23.09.1
Remediation
Patch Available
Event History
Oct 6, 2023
CVE Published
via MITRE·11:28 PM
Data Sourced
via MITRE·11:28 PM
DescriptionSeverityWeakness
Oct 7, 2023
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-5182.
2
What is the severity of CVE-2023-5182?
The severity of CVE-2023-5182 is medium with a CVSS score of 5.5.
3
How can an attacker exploit this vulnerability?
An attacker in the adm group could exploit this vulnerability to find hashed passwords and possibly escalate their privilege.
4
Which version of subiquity is affected by this vulnerability?
Subiquity version 23.09.1 and earlier are affected by this vulnerability.
5
Is there a fix available?
Yes, the fix for this vulnerability is available in the latest version of subiquity.