CVE-2023-5182
Publication date 4 October 2023
Last updated 26 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find hashed passwords and possibly escalate their privilege.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| subiquity | ||
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Ignored see notes | |
| 20.04 LTS focal | Ignored end of standard support, was ignored [see notes] | |
| 18.04 LTS bionic | Ignored end of standard support | |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release |
Notes
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.5 · Medium
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N