ALT-PU-2020-1691-1
Package cloud-init updated to version 20.1-alt1 for branch sisyphus in task 249517.
Closed vulnerabilities
Published: 2020-02-05
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2020-8631
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.
Severity: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
References:
- openSUSE-SU-2020:0400
- openSUSE-SU-2020:0400
- https://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795
- https://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795
- https://github.com/canonical/cloud-init/pull/204
- https://github.com/canonical/cloud-init/pull/204
- [debian-lts-announce] 20200221 [SECURITY] [DLA 2113-1] cloud-init security update
- [debian-lts-announce] 20200221 [SECURITY] [DLA 2113-1] cloud-init security update
Published: 2020-02-05
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2020-8632
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
Severity: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
References:
- openSUSE-SU-2020:0400
- openSUSE-SU-2020:0400
- https://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795
- https://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795
- https://github.com/canonical/cloud-init/pull/189
- https://github.com/canonical/cloud-init/pull/189
- [debian-lts-announce] 20200221 [SECURITY] [DLA 2113-1] cloud-init security update
- [debian-lts-announce] 20200221 [SECURITY] [DLA 2113-1] cloud-init security update