[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2021-1486 --- cloud-init

ID: oval:org.secpod.oval:def:1601426Date: (C)2021-03-22   (M)2023-05-11
Class: PATCHFamily: unix




A flaw was found in cloud-init, where it uses the random.choice function when creating sensitive random strings used for generating a random password in new instances. Depending on the instance configuration, a remote or local attacker may abuse this vulnerability to guess the password of the victim user. A flaw was found in cloud-init, where it uses short passwords when generating a random password in new instances. Depending on the instance configuration, a remote or local attacker may abuse this vulnerability to guess the password of the victim user. A vulnerability was discovered in cloud-init which can improperly disclose randomly generated passwords as part of the chpasswd module. The fix prevents the generated password from being written to a world-readable log file on the local disk

Platform:
Amazon Linux AMI
Product:
cloud-init
Reference:
ALAS-2021-1486
CVE-2020-8631
CVE-2020-8632
CVE-2021-3429
CVE    3
CVE-2021-3429
CVE-2020-8631
CVE-2020-8632

© SecPod Technologies