Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and trivially extract the private key from it.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-19609 juju/utils leaks private key in certs
Github GHSA Github GHSA GHSA-h34r-jxqm-qgpr juju/utils leaks private key in certs
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 11 Sep 2025 01:15:00 +0900

Type Values Removed Values Added
First Time appeared Canonical
Canonical juju\/utils
CPEs cpe:2.3:a:canonical:juju\/utils:*:*:*:*:*:go:*:*
Vendors & Products Canonical
Canonical juju\/utils

Wed, 02 Jul 2025 00:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Jul 2025 19:45:00 +0900

Type Values Removed Values Added
Description Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and trivially extract the private key from it.
Title Key leakage in juju/utils certificates
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2025-07-01T14:30:51.639Z

Reserved: 2025-06-18T08:48:41.677Z

Link: CVE-2025-6224

cve-icon Vulnrichment

Updated: 2025-07-01T14:30:42.574Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-01T11:15:21.770

Modified: 2025-09-10T16:08:34.040

Link: CVE-2025-6224

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses