QID 352245
Date Published: 2021-03-25
QID 352245: Amazon Linux Security Advisory for cloud-init: ALAS-2021-1486
<DIV> Issue Overview:
A flaw was found in cloud-init, where it uses the random.choice function when creating sensitive random strings used for generating a random password in new instances. Depending on the instance configuration, a remote or local attacker may abuse this vulnerability to guess the password of the victim user. (CVE-2020-8631 )
A flaw was found in cloud-init, where it uses short passwords when generating a random password in new instances. Depending on the instance configuration, a remote or local attacker may abuse this vulnerability to guess the password of the victim user. (CVE-2020-8632 )
A vulnerability was discovered in cloud-init which can improperly disclose randomly generated passwords as part of the chpasswd module. The fix prevents the generated password from being written to a world-readable log file on the local disk. (CVE-2021-3429 )
</DIV>Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.
- ALAS-2021-1486 -
alas.aws.amazon.com/ALAS-2021-1486.html
CVEs related to QID 352245
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS-2021-1486 | Amazon Linux | cloud-init (0.7.6-43.23.amzn1) on noarch |
|
| ALAS-2021-1486 | Amazon Linux | cloud-init (0.7.6-43.23.amzn1) on src |
|