CVE-2025-15480: Senstive information disclosure was affecting ubuntu-desktop-provision
In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15480?
CVE-2025-15480 has been classified as a moderate severity vulnerability due to its potential to leak sensitive user credentials.
How do I fix CVE-2025-15480?
To fix CVE-2025-15480, update ubuntu-desktop-provision to version 24.04.5 or later.
What types of information can be leaked by CVE-2025-15480?
CVE-2025-15480 can leak sensitive user credentials during bug reporting after installation failures.
What software is affected by CVE-2025-15480?
CVE-2025-15480 affects ubuntu-desktop-provision version 24.04.4 on Ubuntu.
Is there a workaround for CVE-2025-15480?
Currently, the best approach to mitigate CVE-2025-15480 is to upgrade to the latest version of ubuntu-desktop-provision.