CVE-2020-8631
05.02.2020, 14:15
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.Enginsight
| Vendor | Product | Version |
|---|---|---|
| canonical | cloud-init | 𝑥 ≤ 19.4 |
| opensuse | leap | 15.1 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References