Untriaged
Permalink
CVE-2023-1786
5.5 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
sensitive data exposure in cloud-init logs
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
References
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://github.com/canonical/cloud-init/commit/a378b7e4f47375458651c0972e7cd813… patch
- https://bugs.launchpad.net/cloud-init/+bug/2013967 issue-tracking
- https://ubuntu.com/security/notices/USN-6042-1 vendor-advisory
- https://github.com/canonical/cloud-init/commit/a378b7e4f47375458651c0972e7cd813… patch x_transferred
- https://bugs.launchpad.net/cloud-init/+bug/2013967 issue-tracking x_transferred
- https://ubuntu.com/security/notices/USN-6042-1 vendor-advisory x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://github.com/canonical/cloud-init/commit/a378b7e4f47375458651c0972e7cd813… patch
- https://bugs.launchpad.net/cloud-init/+bug/2013967 issue-tracking
- https://ubuntu.com/security/notices/USN-6042-1 vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://ubuntu.com/security/notices/USN-6042-1 vendor-advisory x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
- https://github.com/canonical/cloud-init/commit/a378b7e4f47375458651c0972e7cd813… patch x_transferred
- https://bugs.launchpad.net/cloud-init/+bug/2013967 issue-tracking x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj…
- https://github.com/canonical/cloud-init/commit/a378b7e4f47375458651c0972e7cd813… patch
- https://bugs.launchpad.net/cloud-init/+bug/2013967 issue-tracking
- https://ubuntu.com/security/notices/USN-6042-1 vendor-advisory
- https://github.com/canonical/cloud-init/commit/a378b7e4f47375458651c0972e7cd813… patch x_transferred
- https://bugs.launchpad.net/cloud-init/+bug/2013967 issue-tracking x_transferred
- https://ubuntu.com/security/notices/USN-6042-1 vendor-advisory x_transferred
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproj… x_transferred
Affected products
cloud-init
- <23.1.2
Matching in nixpkgs
pkgs.cloud-init
Provides configuration and customization of cloud instance
-
nixos-unstable -
- nixpkgs-unstable 25.2
Package maintainers
-
@jfroche Jean-François Roche <jfroche@pyxel.be>
-
@illustris Harikrishnan R <me@illustris.tech>