Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-3429

Опубликовано: 19 апр. 2023
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:canonical:cloud-init:*:*:*:*:*:*:*:*
Версия до 21.2 (исключая)

EPSS

Процентиль: 17%
0.00054
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-532
CWE-532
CWE-532

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

CVSS3: 5.5
redhat
больше 4 лет назад

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

CVSS3: 5.5
debian
больше 2 лет назад

When instructing cloud-init to set a random password for a new user ac ...

rocky
почти 4 года назад

Moderate: cloud-init security update

CVSS3: 5.5
github
больше 2 лет назад

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

EPSS

Процентиль: 17%
0.00054
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-532
CWE-532
CWE-532