Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-3429

Опубликовано: 19 апр. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.5

Описание

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

РелизСтатусПримечание
bionic

released

21.1-19-gbad84ad4-0ubuntu1~18.04.1
devel

not-affected

21.1-19-gbad84ad4-0ubuntu2
esm-infra-legacy/trusty

DNE

esm-infra/bionic

released

21.1-19-gbad84ad4-0ubuntu1~18.04.1
esm-infra/focal

released

21.1-19-gbad84ad4-0ubuntu1~20.04.1
esm-infra/xenial

released

21.1-19-gbad84ad4-0ubuntu1~16.04.1
focal

released

21.1-19-gbad84ad4-0ubuntu1~20.04.1
groovy

released

21.1-19-gbad84ad4-0ubuntu1~20.10.1
precise/esm

DNE

trusty

ignored

end of standard support

Показывать по

Ссылки на источники

EPSS

Процентиль: 17%
0.00054
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
больше 4 лет назад

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

CVSS3: 5.5
nvd
больше 2 лет назад

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

CVSS3: 5.5
debian
больше 2 лет назад

When instructing cloud-init to set a random password for a new user ac ...

rocky
больше 4 лет назад

Moderate: cloud-init security update

CVSS3: 5.5
github
больше 2 лет назад

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.

EPSS

Процентиль: 17%
0.00054
Низкий

5.5 Medium

CVSS3