CVE-2020-11932: low-severity vulnerability in Canonical Subiquity
Subiquity server installer logged LUKS full disk encryption password
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
The Subiquity Ubuntu Server installer accidentally recorded the LUKS disk encryption password in its logs. This means the password could be exposed if someone accessed the installer logs, compromising the security of the encrypted disk.
CWE-532 (Insertion of Sensitive Information into Log File) vulnerability where LUKS full disk encryption passwords entered during installation were written to plaintext log files. An attacker with read access to installer logs could extract the password, bypassing disk encryption protections. The vulnerability requires the user to set up LUKS encryption during installation.