CVE-2023-1786
Summary
| CVE | CVE-2023-1786 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-26 23:15:00 UTC |
| Updated | 2023-05-08 18:38:00 UTC |
| Description | Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Bug #2013967 “cloud-init leaks credentials " : Bugs : cloud-init |
MISC |
bugs.launchpad.net |
|
| [SECURITY] Fedora 38 Update: cloud-init-23.1.2-1.fc38 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| Make user/vendor data sensitive and remove log permissions (#2144) · canonical/cloud-init@a378b7e · GitHub |
MISC |
github.com |
|
| USN-6042-1: Cloud-init vulnerability | Ubuntu security notices | Ubuntu |
MISC |
ubuntu.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160569 Oracle Enterprise Linux Security Update for cloud-init (ELSA-2023-12299)
- 160570 Oracle Enterprise Linux Security Update for cloud-init (ELSA-2023-12298)
- 161074 Oracle Enterprise Linux Security Update for cloud-init (ELSA-2023-6371)
- 161153 Oracle Enterprise Linux Security Update for cloud-init (ELSA-2023-6943)
- 199308 Ubuntu Security Notification for Cloud-init Vulnerability (USN-6042-1)
- 242333 Red Hat Update for cloud-init security (RHSA-2023:6371)
- 242416 Red Hat Update for cloud-init security (RHSA-2023:6943)
- 284157 Fedora Security Update for cloud (FEDORA-2023-c17dde4052)
- 355421 Amazon Linux Security Advisory for cloud-init : ALAS2023-2023-196
- 503153 Alpine Linux Security Update for cloud-init
- 505994 Alpine Linux Security Update for cloud-init
- 673280 EulerOS Security Update for cloud-init (EulerOS-SA-2023-2576)
- 673307 EulerOS Security Update for cloud-init (EulerOS-SA-2023-2606)
- 673422 EulerOS Security Update for cloud-init (EulerOS-SA-2023-2855)
- 673451 EulerOS Security Update for cloud-init (EulerOS-SA-2023-3116)
- 673561 EulerOS Security Update for cloud-init (EulerOS-SA-2023-2805)
- 674039 EulerOS Security Update for cloud-init (EulerOS-SA-2023-2838)
- 674094 EulerOS Security Update for cloud-init (EulerOS-SA-2023-2781)
- 691158 Free Berkeley Software Distribution (FreeBSD) Security Update for cloud (02562a78-e6b7-11ed-b0ce-b42e991fc52e)
- 755608 SUSE Enterprise Linux Security Update for cloud-init (SUSE-SU-2024:0128-1)
- 907038 Common Base Linux Mariner (CBL-Mariner) Security Update for cloud-init (26342-1)
- 907066 Common Base Linux Mariner (CBL-Mariner) Security Update for cloud-init (26343-1)
- 941354 AlmaLinux Security Update for cloud-init (ALSA-2023:6371)
- 941443 AlmaLinux Security Update for cloud-init (ALSA-2023:6943)