CVE-2025-15480
In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs.
Scoring
- Severity
- LOW
- CVSS base score
- 2.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U
- EPSS probability
- 0.31%
- CWE
- CWE-1258
- Published
- 2026-04-09
- Last modified
- 2026-04-10
Affected products
- Canonical Ubuntu
Weakness type
Related vulnerabilities
- CVE-2026-79727 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-80239 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-66432 — WordPress WPJAM Basic plugin <= 7.0.2.1 - Sensitive Data Exposure vulnerability
- CVE-2026-52696 — WordPress JetBlog plugin <= 2.4.8 - Sensitive Data Exposure vulnerability
- CVE-2025-14551 — Senstive information disclosure was affecting subiquity
- CVE-2026-26948 — Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G...
- CVE-2025-26482 — Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure...
- CVE-2025-32257 — WordPress 1 Click WordPress Migration Plugin <= 2.2 - Sensitive Data Exposure vulnerability