5.5 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
sensitive data exposure in cloud-init logs
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.
References
- https://github.com/canonical/cloud-init/commit/4d467b14363d800b2185b89790d57871… patch
- https://ubuntu.com/security/notices/USN-5496-1 vendor-advisory
- https://github.com/canonical/cloud-init/commit/4d467b14363d800b2185b89790d57871… x_transferred patch
- https://ubuntu.com/security/notices/USN-5496-1 vendor-advisory x_transferred
- https://github.com/canonical/cloud-init/commit/4d467b14363d800b2185b89790d57871… patch
- https://ubuntu.com/security/notices/USN-5496-1 vendor-advisory
- https://github.com/canonical/cloud-init/commit/4d467b14363d800b2185b89790d57871… x_transferred patch
- https://ubuntu.com/security/notices/USN-5496-1 vendor-advisory x_transferred
Affected products
- <23.0
Matching in nixpkgs
pkgs.cloud-init
Provides configuration and customization of cloud instance
-
nixos-unstable -
- nixpkgs-unstable 25.2
Package maintainers
-
@jfroche Jean-François Roche <jfroche@pyxel.be>
-
@illustris Harikrishnan R <me@illustris.tech>