Описание
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 23.1.2-0ubuntu0~18.04.1 |
| devel | not-affected | 23.2-0ubuntu1 |
| esm-infra/bionic | released | 23.1.2-0ubuntu0~18.04.1 |
| esm-infra/focal | released | 23.1.2-0ubuntu0~20.04.1 |
| esm-infra/xenial | released | 21.1-19-gbad84ad4-0ubuntu1~16.04.4 |
| focal | released | 23.1.2-0ubuntu0~20.04.1 |
| jammy | released | 23.1.2-0ubuntu0~22.04.1 |
| kinetic | released | 23.1.2-0ubuntu0~22.10.1 |
| lunar | released | 23.1.2-0ubuntu0~23.04.1 |
| trusty | ignored | end of standard support |
Показывать по
10
EPSS
Процентиль: 4%
0.0002
Низкий
5.5 Medium
CVSS3
Связанные уязвимости
CVSS3: 5.5
redhat
больше 2 лет назад
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
CVSS3: 5.5
nvd
больше 2 лет назад
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
CVSS3: 5.5
debian
больше 2 лет назад
Sensitive data could be exposed in logs of cloud-init before version 2 ...
EPSS
Процентиль: 4%
0.0002
Низкий
5.5 Medium
CVSS3