Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcwr-9f5c-qg65

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.

In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.

EPSS

Процентиль: 29%
0.00365
Низкий

Дефекты

CWE-521
CWE-522

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 6 лет назад

In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.

CVSS3: 8.1
redhat
больше 6 лет назад

In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.

CVSS3: 5.5
nvd
больше 6 лет назад

In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.

CVSS3: 5.5
msrc
почти 6 лет назад

In cloud-init through 19.4 rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value which makes it easier for attackers to guess passwords.

CVSS3: 5.5
debian
больше 6 лет назад

In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_ ...

EPSS

Процентиль: 29%
0.00365
Низкий

Дефекты

CWE-521
CWE-522