Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 17 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 17 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical ubuntu Desktop Provision
|
|
| CPEs | cpe:2.3:a:canonical:ubuntu_desktop_provision:24.04.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Canonical ubuntu Desktop Provision
|
|
| Metrics |
cvssV3_1
|
Fri, 10 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical ubuntu |
|
| Vendors & Products |
Canonical
Canonical ubuntu |
Thu, 09 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs. | |
| Title | Senstive information disclosure was affecting ubuntu-desktop-provision | |
| Weaknesses | CWE-1258 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-04-10T13:57:17.350Z
Reserved: 2026-01-07T14:28:47.147Z
Link: CVE-2025-15480
Updated: 2026-04-10T13:56:58.292Z
Status : Analyzed
Published: 2026-04-09T16:16:25.250
Modified: 2026-04-17T20:18:08.243
Link: CVE-2025-15480
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:32:30Z