| { |
| "schema_version": "1.3.1", |
| "id": "GO-2025-3798", |
| "modified": "0001-01-01T00:00:00Z", |
| "published": "0001-01-01T00:00:00Z", |
| "aliases": [ |
| "CVE-2025-6224", |
| "GHSA-h34r-jxqm-qgpr" |
| ], |
| "summary": "Leaks private key in certs in github.com/juju/utils", |
| "details": "Leaks private key in certs in github.com/juju/utils", |
| "affected": [ |
| { |
| "package": { |
| "name": "github.com/juju/utils", |
| "ecosystem": "Go" |
| }, |
| "ranges": [ |
| { |
| "type": "SEMVER", |
| "events": [ |
| { |
| "introduced": "0" |
| } |
| ] |
| } |
| ], |
| "ecosystem_specific": {} |
| }, |
| { |
| "package": { |
| "name": "github.com/juju/utils/v2", |
| "ecosystem": "Go" |
| }, |
| "ranges": [ |
| { |
| "type": "SEMVER", |
| "events": [ |
| { |
| "introduced": "0" |
| } |
| ] |
| } |
| ], |
| "ecosystem_specific": {} |
| }, |
| { |
| "package": { |
| "name": "github.com/juju/utils/v3", |
| "ecosystem": "Go" |
| }, |
| "ranges": [ |
| { |
| "type": "SEMVER", |
| "events": [ |
| { |
| "introduced": "0" |
| } |
| ] |
| } |
| ], |
| "ecosystem_specific": {} |
| }, |
| { |
| "package": { |
| "name": "github.com/juju/utils/v4", |
| "ecosystem": "Go" |
| }, |
| "ranges": [ |
| { |
| "type": "SEMVER", |
| "events": [ |
| { |
| "introduced": "0" |
| }, |
| { |
| "fixed": "4.0.4" |
| } |
| ] |
| } |
| ], |
| "ecosystem_specific": { |
| "imports": [ |
| { |
| "path": "github.com/juju/utils/v4/winrm", |
| "symbols": [ |
| "Client.Password", |
| "Client.Ping", |
| "Client.Run", |
| "Client.Secure", |
| "ClientConfig.Validate", |
| "ClientConfig.password", |
| "NewClient", |
| "NewX509", |
| "TTYGetPasswd", |
| "X509.CACert", |
| "X509.ClientCert", |
| "X509.ClientKey", |
| "X509.LoadCACert", |
| "X509.LoadClientCert", |
| "X509.Reset", |
| "X509.read", |
| "X509.write", |
| "confExists", |
| "newCredentials" |
| ] |
| }, |
| { |
| "path": "github.com/juju/utils/v4/cert", |
| "symbols": [ |
| "NewCA", |
| "NewClientCert", |
| "NewLeaf", |
| "bigIntHash", |
| "getPublicKey", |
| "newSerialNumber" |
| ] |
| } |
| ] |
| } |
| } |
| ], |
| "references": [ |
| { |
| "type": "ADVISORY", |
| "url": "https://github.com/juju/utils/security/advisories/GHSA-h34r-jxqm-qgpr" |
| }, |
| { |
| "type": "FIX", |
| "url": "https://github.com/juju/utils/commit/766f27d7bcd10433453a9764509a864c17a46a76" |
| }, |
| { |
| "type": "WEB", |
| "url": "https://github.com/juju/utils/releases/tag/v4.0.4" |
| } |
| ], |
| "database_specific": { |
| "url": "https://pkg.go.dev/vuln/GO-2025-3798", |
| "review_status": "REVIEWED" |
| } |
| } |