In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 09 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs. | |
| Title | Senstive information disclosure was affecting ubuntu-desktop-provision | |
| Weaknesses | CWE-1258 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-04-09T15:02:14.066Z
Reserved: 2026-01-07T14:28:47.147Z
Link: CVE-2025-15480
No data.
Status : Received
Published: 2026-04-09T16:16:25.250
Modified: 2026-04-09T16:16:25.250
Link: CVE-2025-15480
No data.
OpenCVE Enrichment
No data.
Weaknesses