Vulnerability Description
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Cloud-Init | < 23.1.2 |
| Canonical | Ubuntu Linux | 16.04 |
| Fedoraproject | Fedora | 38 |
Related Weaknesses (CWE)
References
- https://bugs.launchpad.net/cloud-init/+bug/2013967Issue Tracking
- https://github.com/canonical/cloud-init/commit/a378b7e4f47375458651c0972e7cd813fPatch
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing ListThird Party Advisory
- https://ubuntu.com/security/notices/USN-6042-1Third Party Advisory
- https://bugs.launchpad.net/cloud-init/+bug/2013967Issue Tracking
- https://github.com/canonical/cloud-init/commit/a378b7e4f47375458651c0972e7cd813fPatch
- https://lists.fedoraproject.org/archives/list/[email protected]Mailing ListThird Party Advisory
- https://ubuntu.com/security/notices/USN-6042-1Third Party Advisory
FAQ
What is CVE-2023-1786?
CVE-2023-1786 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
How severe is CVE-2023-1786?
CVE-2023-1786 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-1786?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Cloud-Init, Canonical Ubuntu Linux, Fedoraproject Fedora.