Логотип exploitDog
bind:"CVE-2020-8631" OR bind:"CVE-2020-8632" OR bind:"CVE-2018-10896"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2020-8631" OR bind:"CVE-2020-8632" OR bind:"CVE-2018-10896"

Количество 22

Количество 22

github логотип

GHSA-rwhw-r234-9p3m

больше 3 лет назад

The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys, and being able to impersonate one another or conduct man-in-the-middle attacks.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xcwr-9f5c-qg65

больше 3 лет назад

In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-rwhw-r234-9p3m

The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys, and being able to impersonate one another or conduct man-in-the-middle attacks.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xcwr-9f5c-qg65

In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу