Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-1786

Опубликовано: 26 апр. 2023
Источник: debian

Описание

Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cloud-initfixed23.2-1package
cloud-initno-dsabookwormpackage
cloud-initno-dsabullseyepackage
cloud-initno-dsabusterpackage

Примечания

  • https://bugs.launchpad.net/cloud-init/+bug/2013967

  • https://github.com/canonical/cloud-init/commit/a378b7e4f47375458651c0972e7cd813f6fe0a6b (23.2)

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.

CVSS3: 5.5
redhat
больше 2 лет назад

Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.

CVSS3: 5.5
nvd
больше 2 лет назад

Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.

CVSS3: 5.5
msrc
больше 2 лет назад

Описание отсутствует

suse-cvrf
больше 1 года назад

Security update for cloud-init