CVE-2023-5182: Canonical Subiquity

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find hashed passwords and possibly escalate their privilege.

Affected products

  • Canonical Subiquity: up to and including 23.09.1

Published 2023-10-07. Last modified 2026-06-17.