Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade cloud-init | Aug 22, 2024 | Apr 19, 2023 |
| Debian | — | Upgrade cloud-init | Jul 30, 2024 | Apr 19, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade cloud-init | Jul 18, 2023 | Apr 19, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade cloud-init | Jan 10, 2024 | Apr 19, 2023 |
| Huawei Euleros 2_0_sp8 | — | Upgrade cloud-init | Jan 10, 2024 | Apr 19, 2023 |
| Huawei Euleros 2_0_sp9 | — | Upgrade cloud-init | Aug 9, 2023 | Apr 19, 2023 |
| Suse | — | Upgrade cloud-init-docUpgrade cloud-initUpgrade cloud-init-config-suse | Jun 26, 2023 | Apr 19, 2023 |
| Ubuntu | — | Upgrade cloud-init | Mar 22, 2023 | Jun 29, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub