CVE-2019-0816
published 2019-04-09CVE-2019-0816: A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH…
PriorityP423medium5.1CVSS 3.0
AVLACHPRNUINSUCNIHAN
EPSS
1.40%
69.4th percentile
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | cloud-init | >= 0 < 18.3-6 | 18.3-6 |
| canonical | cloud-init | >= 0 < 18.3-6 | 18.3-6 |
| canonical | cloud-init | >= 0 < 18.3-6 | 18.3-6 |
| canonical | cloud-init | >= 0 < 18.3-6 | 18.3-6 |
| canonical | ubuntu_linux | — | — |
| debian | cloud-init | < cloud-init 18.3-6 (bookworm) | cloud-init 18.3-6 (bookworm) |
| microsoft | ubuntu_server | — | — |
| msrc | ubuntuserver_18.04-lts | — | — |
CVSS provenance
nvdv3.05.1MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
osv5.1MEDIUM
vendor_debian5.1LOW
vendor_msrc5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gjp8-2rjx-f9mg: A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azur
ghsa_unreviewed·2022-05-13
CVE-2019-0816 [MEDIUM] CWE-706 GHSA-gjp8-2rjx-f9mg: A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azur
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.
OSV
CVE-2019-0816: A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azur
osv·2019-04-09·CVSS 5.1
CVE-2019-0816 [MEDIUM] CVE-2019-0816: A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azur
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.
Microsoft
Azure SSH Keypairs Security Feature Bypass Vulnerability
vendor_msrc·2019-03-12·CVSS 5.1
CVE-2019-0816 [MEDIUM] Azure SSH Keypairs Security Feature Bypass Vulnerability
Azure SSH Keypairs Security Feature Bypass Vulnerability
Description: A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init. Extraneous Microsoft service public keys can be unexpectedly added to the VM authorized keys file in the limited scenarios described in 4491476. For more information on how to know if you are affected and how to protect yourself, please see 4491476.
This update addresses this vulnerability by preventing these keys from being added.
Azure: Azure
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Red Hat
cloud-init: extra ssh keys added to authorized_keys on the Azure platform
vendor_redhat·2019-03-05·CVSS 5.1
CVE-2019-0816 [MEDIUM] CWE-285 cloud-init: extra ssh keys added to authorized_keys on the Azure platform
cloud-init: extra ssh keys added to authorized_keys on the Azure platform
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.
Mitigation: See steps from https://support.microsoft.com/en-us/help/4491476/extraneous-ssh-public-keys-added-to-authorized-keys-file-on-linux-vm
Debian
CVE-2019-0816: cloud-init - A security feature bypass exists in Azure SSH Keypairs, due to a change in the p...
vendor_debian·2019·CVSS 5.1
CVE-2019-0816 [MEDIUM] CVE-2019-0816: cloud-init - A security feature bypass exists in Azure SSH Keypairs, due to a change in the p...
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.
Scope: local
bookworm: resolved (fixed in 18.3-6)
bullseye: resolved (fixed in 18.3-6)
forky: resolved (fixed in 18.3-6)
sid: resolved (fixed in 18.3-6)
trixie: resolved (fixed in 18.3-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-0816 cloud-init: extra ssh keys added to authorized_keys [epel-6]
bugzilla·2019-03-13·CVSS 5.1
CVE-2019-0816 [MEDIUM] CVE-2019-0816 cloud-init: extra ssh keys added to authorized_keys [epel-6]
CVE-2019-0816 cloud-init: extra ssh keys added to authorized_keys [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg
Bugzilla
CVE-2019-0816 cloud-init: extra ssh keys added to authorized_keys [fedora-all]
bugzilla·2019-03-13·CVSS 5.1
CVE-2019-0816 [MEDIUM] CVE-2019-0816 cloud-init: extra ssh keys added to authorized_keys [fedora-all]
CVE-2019-0816 cloud-init: extra ssh keys added to authorized_keys [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2019-0816 cloud-init: extra ssh keys added to authorized_keys on the Azure platform
bugzilla·2019-02-22·CVSS 5.1
CVE-2019-0816 [MEDIUM] CVE-2019-0816 cloud-init: extra ssh keys added to authorized_keys on the Azure platform
CVE-2019-0816 cloud-init: extra ssh keys added to authorized_keys on the Azure platform
A vulnerability was found in the Azure plugin of cloud-init. The entire list of certificates and public keys exposed from the wireserver is added to the authorized_keys file for the user-to-be-provisioned, regardless of whether they belong to the user or not.
Upstream commit:
https://code.launchpad.net/~jasonzio/cloud-init/+git/cloud-init/+merge/363445
Discussion:
External References:
https://support.microsoft.com/en-us/help/4491476/extraneous-ssh-public-keys-added-to-authorized-keys-file-on-linux-vm
---
Mitigation:
See steps from https://support.microsoft.com/en-us/help/4491476/extraneous-ssh-public-keys-added-to-authorized-keys-file-on-linux-vm
---
Created cloud-init tracking bugs for this
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00018.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0816http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00018.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0816
2019-04-09
Published