netplan leaks the private key of wireguard to local users. Versions after 1.0 are not affected.
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
Link | Tags |
---|---|
https://github.com/canonical/netplan/commit/4c39b75b5c6ae7d976bda6da68da60d9a7f085ee | patch |
https://bugs.launchpad.net/netplan/+bug/1987842 | vendor advisory issue tracking |
https://bugs.launchpad.net/ubuntu/+source/netplan.io/+bug/2065738 | vendor advisory issue tracking exploit |
https://www.cve.org/CVERecord?id=CVE-2022-4968 | issue tracking us government resource |