Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-6224

Опубликовано: 01 июл. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and trivially extract the private key from it.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:canonical:juju\/utils:*:*:*:*:*:go:*:*
Версия от 4.0.0 (включая) до 4.0.4 (исключая)

EPSS

Процентиль: 2%
0.00014
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 месяца назад

Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and trivially extract the private key from it.

CVSS3: 6.5
github
4 месяца назад

juju/utils leaks private key in certs

EPSS

Процентиль: 2%
0.00014
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-312