CVE-2020-8632
05.02.2020, 14:15
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.Enginsight
Vendor | Product | Version |
---|---|---|
canonical | cloud-init | 𝑥 ≤ 19.4 |
opensuse | leap | 15.1 |
debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
cloud-init |
|
Common Weakness Enumeration
References