Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3429

Опубликовано: 19 апр. 2023
Источник: debian
EPSS Низкий

Описание

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cloud-initfixed20.4.1-2package
cloud-initfixed20.2-2~deb10u2busterpackage

Примечания

  • https://github.com/canonical/cloud-init/commit/b794d426b9ab43ea9d6371477466070d86e10668

EPSS

Процентиль: 17%
0.00054
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

CVSS3: 5.5
redhat
больше 4 лет назад

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

CVSS3: 5.5
nvd
больше 2 лет назад

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

rocky
почти 4 года назад

Moderate: cloud-init security update

CVSS3: 5.5
github
больше 2 лет назад

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

EPSS

Процентиль: 17%
0.00054
Низкий