← Back

CVE-2025-6224

nvd nist
Published: Jul 1, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and trivially extract the private key from it.

Affected (1)

1 product
Juju/utils
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 4.0.0 to 4.0.4

References (1)

Source: security@ubuntu.com
ExploitVendor Advisory

Timeline

No history available yet.