SCA: security update for github.com/juju/utils/v4/cert (GHSA-h34r-jxqm-qgpr)

medium Tenable Cloud Security Plugin ID 437046

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If
this certificate were then transferred over the network in plaintext, an attacker listening on that
network could sniff the certificate and trivially extract the private key from it. (CVE-2025-6224)

See Also

https://github.com/advisories/GHSA-h34r-jxqm-qgpr

Plugin Details

Severity: Medium

ID: 437046

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 1/27/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2025-6224

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/1/2025

Vulnerability Publication Date: 7/1/2025

Reference Information

CVE: CVE-2025-6224

cwe: CWE-312