Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2019-0816

Опубликовано: 12 мар. 2019
Источник: msrc
EPSS Низкий

Описание

Azure SSH Keypairs Security Feature Bypass Vulnerability

A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init. Extraneous Microsoft service public keys can be unexpectedly added to the VM authorized keys file in the limited scenarios described in 4491476. For more information on how to know if you are affected and how to protect yourself, please see 4491476.

This update addresses this vulnerability by preventing these keys from being added.

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 28%
0.001
Низкий

Связанные уязвимости

CVSS3: 5.1
ubuntu
больше 6 лет назад

A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.

CVSS3: 5.4
redhat
больше 6 лет назад

A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.

CVSS3: 5.1
nvd
больше 6 лет назад

A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.

CVSS3: 5.1
debian
больше 6 лет назад

A security feature bypass exists in Azure SSH Keypairs, due to a chang ...

suse-cvrf
почти 6 лет назад

Security update for cloud-init

EPSS

Процентиль: 28%
0.001
Низкий