Permalink
CVE-2023-1786
5.5 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
by @fricklerhandwerk Activity log
- Created automatic suggestion
- @fricklerhandwerk dismissed
sensitive data exposure in cloud-init logs
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
References
-
https://bugs.launchpad.net/cloud-init/+bug/2013967 issue-tracking
-
https://ubuntu.com/security/notices/USN-6042-1 vendor-advisory
-
-
-
https://bugs.launchpad.net/cloud-init/+bug/2013967 issue-tracking
-
https://ubuntu.com/security/notices/USN-6042-1 vendor-advisory
-
-
-
https://bugs.launchpad.net/cloud-init/+bug/2013967 issue-tracking
-
https://ubuntu.com/security/notices/USN-6042-1 vendor-advisory
-
-
-
https://bugs.launchpad.net/cloud-init/+bug/2013967 issue-tracking
-
https://ubuntu.com/security/notices/USN-6042-1 vendor-advisory
-
-
Affected products
cloud-init
- <23.1.2
Matching in nixpkgs
pkgs.cloud-init
Provides configuration and customization of cloud instance
Package maintainers
-
@jfroche Jean-François Roche <jfroche@pyxel.be>
-
@illustris Harikrishnan R <me@illustris.tech>