Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-3429

Опубликовано: 19 апр. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 5.5

Описание

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

РелизСтатусПримечание
bionic

released

21.1-19-gbad84ad4-0ubuntu1~18.04.1
devel

not-affected

21.1-19-gbad84ad4-0ubuntu2
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

21.1-19-gbad84ad4-0ubuntu1~18.04.1
esm-infra/focal

not-affected

21.1-19-gbad84ad4-0ubuntu1~20.04.1
esm-infra/xenial

not-affected

21.1-19-gbad84ad4-0ubuntu1~16.04.1
focal

released

21.1-19-gbad84ad4-0ubuntu1~20.04.1
groovy

released

21.1-19-gbad84ad4-0ubuntu1~20.10.1
precise/esm

DNE

trusty

ignored

end of standard support

Показывать по

Ссылки на источники

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
больше 4 лет назад

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

CVSS3: 5.5
nvd
больше 2 лет назад

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

CVSS3: 5.5
debian
больше 2 лет назад

When instructing cloud-init to set a random password for a new user ac ...

rocky
почти 4 года назад

Moderate: cloud-init security update

CVSS3: 5.5
github
больше 2 лет назад

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

5.5 Medium

CVSS3