CVE-2018-10896
published 2018-08-01CVE-2018-10896: The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some…
PriorityP427high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.35%
27.6th percentile
The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys, and being able to impersonate one another or conduct man-in-the-middle attacks.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | cloud-init | — | — |
| canonical | cloud-init | >= 0.6.2 < 18.4 | 18.4 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_cloud-init_21.3-3_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv3.04.6MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
The default cloud-init configuration in cloud-init 0.6.2 and newer included "ssh_deletekeys: 0" disabling cloud-init's deletion of ssh host keys. In some environments this could lead to instances crea
vendor_msrc·2018-08-14·CVSS 7.1
CVE-2018-10896 [HIGH] CWE-321 The default cloud-init configuration in cloud-init 0.6.2 and newer included "ssh_deletekeys: 0" disabling cloud-init's deletion of ssh host keys. In some environments this could lead to instances crea
The default cloud-init configuration in cloud-init 0.6.2 and newer included "ssh_deletekeys: 0" disabling cloud-init's deletion of ssh host keys. In some environments this could lead to instances created by cloning a golden master or template system sharing ssh host keys and being able to impersonate one another or conduct man-in-the-middle attacks.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we
Red Hat
cloud-init: default configuration disabled deletion of SSH host keys
vendor_redhat·2018-07-06·CVSS 7.1
CVE-2018-10896 [HIGH] CWE-321 cloud-init: default configuration disabled deletion of SSH host keys
cloud-init: default configuration disabled deletion of SSH host keys
The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys, and being able to impersonate one another or conduct man-in-the-middle attacks.
The default cloud-init configuration included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys, and being able to impersonate one another or conduct man-in-the-middle attacks.
Package: cloud-init (Red Hat Enterprise Linu
GHSA
GHSA-rwhw-r234-9p3m: The default cloud-init configuration, in cloud-init 0
ghsa_unreviewed·2022-05-13
CVE-2018-10896 [HIGH] CWE-321 GHSA-rwhw-r234-9p3m: The default cloud-init configuration, in cloud-init 0
The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys, and being able to impersonate one another or conduct man-in-the-middle attacks.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10896 cloud-init: default configuration disabled deletion of SSH host keys [fedora-all]
bugzilla·2018-07-06·CVSS 7.1
CVE-2018-10896 [HIGH] CVE-2018-10896 cloud-init: default configuration disabled deletion of SSH host keys [fedora-all]
CVE-2018-10896 cloud-init: default configuration disabled deletion of SSH host keys [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2018-10896 cloud-init: default configuration disabled deletion of SSH host keys [epel-6]
bugzilla·2018-07-06·CVSS 7.1
CVE-2018-10896 [HIGH] CVE-2018-10896 cloud-init: default configuration disabled deletion of SSH host keys [epel-6]
CVE-2018-10896 cloud-init: default configuration disabled deletion of SSH host keys [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template t
Bugzilla
CVE-2018-10896 cloud-init: default configuration disabled deletion of SSH host keys
bugzilla·2018-07-06·CVSS 7.1
CVE-2018-10896 [HIGH] CVE-2018-10896 cloud-init: default configuration disabled deletion of SSH host keys
CVE-2018-10896 cloud-init: default configuration disabled deletion of SSH host keys
A flaw was found in cloud-init. SSH host keys are not regenerated when new VM instances are created in combination with hashicorp packer and cloud-init. This could lead to the Man In The Middle (MITM) attack.
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1574338
Discussion:
Created cloud-init tracking bugs for this issue:
Affects: epel-6 [bug 1598833]
Affects: fedora-all [bug 1598832]
---
Reported upstream:
https://bugs.launchpad.net/cloud-init/+bug/1781094
---
Upstream commit now merged to master:
https://git.launchpad.net/cloud-init/commit/?id=e218c597
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:3050 https://access.redhat.
https://bugs.launchpad.net/cloud-init/+bug/1781094https://bugzilla.redhat.com/show_bug.cgi?id=1574338https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10896https://bugs.launchpad.net/cloud-init/+bug/1781094https://bugzilla.redhat.com/show_bug.cgi?id=1574338https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10896
2018-08-01
Published