CVE-2020-8632
05.02.2020, 14:15
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.Enginsight
| Vendor | Product | Version |
|---|---|---|
| canonical | cloud-init | 𝑥 ≤ 19.4 |
| opensuse | leap | 15.1 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cloud-init |
|
Common Weakness Enumeration
References