[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252212

 
 

909

 
 

196748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2021-1576 --- cloud-init

ID: oval:org.secpod.oval:def:1700540Date: (C)2021-01-15   (M)2023-06-16
Class: PATCHFamily: unix




The default cloud-init configuration included "ssh_deletekeys: 0", disabling cloud-init"s deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys, and being able to impersonate one another or conduct man-in-the-middle attacks. A flaw was found in cloud-init, where it uses the random.choice function when creating sensitive random strings used for generating a random password in new instances. Depending on the instance configuration, a remote or local attacker may abuse this vulnerability to guess the password of the victim user. A flaw was found in cloud-init, where it uses short passwords when generating a random password in new instances. Depending on the instance configuration, a remote or local attacker may abuse this vulnerability to guess the password of the victim user

Platform:
Amazon Linux 2
Product:
cloud-init
Reference:
ALAS2-2021-1576
CVE-2018-10896
CVE-2020-8631
CVE-2020-8632
CVE    3
CVE-2020-8631
CVE-2020-8632
CVE-2018-10896

© SecPod Technologies