Логотип exploitDog
bind:CVE-2025-6224
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-6224

Количество 3

Количество 3

ubuntu логотип

CVE-2025-6224

7 месяцев назад

Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and trivially extract the private key from it.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-6224

7 месяцев назад

Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and trivially extract the private key from it.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-h34r-jxqm-qgpr

7 месяцев назад

juju/utils leaks private key in certs

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-6224

Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and trivially extract the private key from it.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
nvd логотип
CVE-2025-6224

Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and trivially extract the private key from it.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-h34r-jxqm-qgpr

juju/utils leaks private key in certs

CVSS3: 6.5
0%
Низкий
7 месяцев назад

Уязвимостей на страницу