CVE-2020-8631
published 2020-02-05CVE-2020-8631: cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.44%
35.3th percentile
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | cloud-init | <= 19.4 | — |
| canonical | cloud-init | >= 0 < 19.4-2 | 19.4-2 |
| canonical | cloud-init | >= 0 < 19.4-2 | 19.4-2 |
| canonical | cloud-init | >= 0 < 19.4-2 | 19.4-2 |
| canonical | cloud-init | >= 0 < 19.4-2 | 19.4-2 |
| debian | cloud-init | < cloud-init 19.4-2 (bookworm) | cloud-init 19.4-2 (bookworm) |
| debian | debian_linux | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_cloud-init_19.1-5_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
cloud-init through 19.4 relies on Mersenne Twister for a random password which makes it easier for attackers to predict passwords because rand_str in cloudinit/util.py calls the random.choice function
vendor_msrc·2020-02-11·CVSS 5.5
CVE-2020-8631 [MEDIUM] CWE-330 cloud-init through 19.4 relies on Mersenne Twister for a random password which makes it easier for attackers to predict passwords because rand_str in cloudinit/util.py calls the random.choice function
cloud-init through 19.4 relies on Mersenne Twister for a random password which makes it easier for attackers to predict passwords because rand_str in cloudinit/util.py calls the random.choice function.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update th
Red Hat
cloud-init: Use of random.choice when generating random password
vendor_redhat·2020-02-05·CVSS 5.5
CVE-2020-8631 [MEDIUM] CWE-330 cloud-init: Use of random.choice when generating random password
cloud-init: Use of random.choice when generating random password
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.
A flaw was found in cloud-init, where it uses the random.choice function when creating sensitive random strings used for generating a random password in new instances. Depending on the instance configuration, a remote or local attacker may abuse this vulnerability to guess the password of the victim user.
Package: cloud-init (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2020-8631: cloud-init - cloud-init through 19.4 relies on Mersenne Twister for a random password, which ...
vendor_debian·2020·CVSS 5.5
CVE-2020-8631 [MEDIUM] CVE-2020-8631: cloud-init - cloud-init through 19.4 relies on Mersenne Twister for a random password, which ...
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.
Scope: local
bookworm: resolved (fixed in 19.4-2)
bullseye: resolved (fixed in 19.4-2)
forky: resolved (fixed in 19.4-2)
sid: resolved (fixed in 19.4-2)
trixie: resolved (fixed in 19.4-2)
GHSA
GHSA-2r47-hhff-7qcp: cloud-init through 19
ghsa_unreviewed·2022-05-24
CVE-2020-8631 [LOW] CWE-330 GHSA-2r47-hhff-7qcp: cloud-init through 19
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.
OSV
CVE-2020-8631: cloud-init through 19
osv·2020-02-05·CVSS 5.5
CVE-2020-8631 [MEDIUM] CVE-2020-8631: cloud-init through 19
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-8631 cloud-init: Use of random.choice when generating random password [fedora-all]
bugzilla·2020-02-05·CVSS 5.5
CVE-2020-8631 [MEDIUM] CVE-2020-8631 cloud-init: Use of random.choice when generating random password [fedora-all]
CVE-2020-8631 cloud-init: Use of random.choice when generating random password [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2020-8631 cloud-init: Use of random.choice when generating random password [epel-6]
bugzilla·2020-02-05·CVSS 5.5
CVE-2020-8631 [MEDIUM] CVE-2020-8631 cloud-init: Use of random.choice when generating random password [epel-6]
CVE-2020-8631 cloud-init: Use of random.choice when generating random password [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for
Bugzilla
CVE-2020-8631 cloud-init: Use of random.choice when generating random password
bugzilla·2020-02-05·CVSS 5.5
CVE-2020-8631 [MEDIUM] CVE-2020-8631 cloud-init: Use of random.choice when generating random password
CVE-2020-8631 cloud-init: Use of random.choice when generating random password
cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function.
Upstream patch:
https://github.com/canonical/cloud-init/pull/204
https://github.com/canonical/cloud-init/commit/3e2f7356effc9e9cccc5ae945846279804eedc46
References:
https://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795
Discussion:
Created cloud-init tracking bugs for this issue:
Affects: epel-6 [bug 1798733]
Affects: fedora-all [bug 1798732]
---
As cc_set_passwords module could be used to set ssh password authentication as well, the Attack Vector is set to Network.
Confidentiality, Integrit
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00042.htmlhttps://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795https://github.com/canonical/cloud-init/pull/204https://lists.debian.org/debian-lts-announce/2020/02/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00042.htmlhttps://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795https://github.com/canonical/cloud-init/pull/204https://lists.debian.org/debian-lts-announce/2020/02/msg00021.html
2020-02-05
Published