cbcvebase.
CVE-2019-0816
published 2019-04-09

CVE-2019-0816: A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH…

PriorityP423medium5.1CVSS 3.0
AVLACHPRNUINSUCNIHAN
EPSS
1.40%
69.4th percentile
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.

Affected

8 ranges
VendorProductVersion rangeFixed in
canonicalcloud-init>= 0 < 18.3-618.3-6
canonicalcloud-init>= 0 < 18.3-618.3-6
canonicalcloud-init>= 0 < 18.3-618.3-6
canonicalcloud-init>= 0 < 18.3-618.3-6
canonicalubuntu_linux
debiancloud-init< cloud-init 18.3-6 (bookworm)cloud-init 18.3-6 (bookworm)
microsoftubuntu_server
msrcubuntuserver_18.04-lts

CVSS provenance

nvdv3.05.1MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
osv5.1MEDIUM
vendor_debian5.1LOW
vendor_msrc5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.