QID 352248

Date Published: 2021-03-25

QID 352248: Amazon Linux Security Advisory for cloud-init: ALAS2-2021-1620

<DIV> Issue Overview:

A vulnerability was discovered in cloud-init which can improperly disclose randomly generated passwords as part of the chpasswd module. The fix prevents the generated password from being written to a world-readable log file on the local disk. (CVE-2021-3429 )

</DIV>

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as Low - 0 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Please refer to Amazon advisory ALAS-2021-1620 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 352248

    Software Advisories
    Advisory ID Software Component Link
    ALAS-2021-1620 Amazon Linux 2 cloud-init (19.3-43.amzn2) on noarch URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1620.html
    ALAS-2021-1620 Amazon Linux 2 cloud-init (19.3-43.amzn2) on src URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1620.html