Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-8631

Опубликовано: 05 фев. 2020
Источник: debian
EPSS Низкий

Описание

cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cloud-initfixed19.4-2package
cloud-initno-dsabusterpackage
cloud-initno-dsastretchpackage

Примечания

  • https://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795

  • https://github.com/canonical/cloud-init/pull/204

EPSS

Процентиль: 31%
0.00116
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 6 лет назад

cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.

CVSS3: 8.1
redhat
около 6 лет назад

cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.

CVSS3: 5.5
nvd
около 6 лет назад

cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.

CVSS3: 5.5
msrc
больше 5 лет назад

cloud-init through 19.4 relies on Mersenne Twister for a random password which makes it easier for attackers to predict passwords because rand_str in cloudinit/util.py calls the random.choice function.

github
больше 3 лет назад

cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.

EPSS

Процентиль: 31%
0.00116
Низкий