CVE-2020-8632
published 2020-02-05CVE-2020-8632: In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.37%
28.9th percentile
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | cloud-init | <= 19.4 | — |
| canonical | cloud-init | >= 0 < 19.4-2 | 19.4-2 |
| canonical | cloud-init | >= 0 < 19.4-2 | 19.4-2 |
| canonical | cloud-init | >= 0 < 19.4-2 | 19.4-2 |
| canonical | cloud-init | >= 0 < 19.4-2 | 19.4-2 |
| debian | cloud-init | < cloud-init 19.4-2 (bookworm) | cloud-init 19.4-2 (bookworm) |
| debian | debian_linux | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_cloud-init_19.1-5_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xcwr-9f5c-qg65: In cloud-init through 19
ghsa_unreviewed·2022-05-24
CVE-2020-8632 [LOW] CWE-521 GHSA-xcwr-9f5c-qg65: In cloud-init through 19
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
OSV
CVE-2020-8632: In cloud-init through 19
osv·2020-02-05·CVSS 5.5
CVE-2020-8632 [MEDIUM] CVE-2020-8632: In cloud-init through 19
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
Microsoft
In cloud-init through 19.4 rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value which makes it easier for attackers to guess passwords.
vendor_msrc·2020-02-11·CVSS 5.5
CVE-2020-8632 [MEDIUM] CWE-521 In cloud-init through 19.4 rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value which makes it easier for attackers to guess passwords.
In cloud-init through 19.4 rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value which makes it easier for attackers to guess passwords.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mari
Red Hat
cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py
vendor_redhat·2020-02-05·CVSS 5.5
CVE-2020-8632 [MEDIUM] CWE-330 cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py
cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
A flaw was found in cloud-init, where it uses short passwords when generating a random password in new instances. Depending on the instance configuration, a remote or local attacker may abuse this vulnerability to guess the password of the victim user.
Package: cloud-init (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2020-8632: cloud-init - In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwo...
vendor_debian·2020·CVSS 5.5
CVE-2020-8632 [MEDIUM] CVE-2020-8632: cloud-init - In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwo...
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
Scope: local
bookworm: resolved (fixed in 19.4-2)
bullseye: resolved (fixed in 19.4-2)
forky: resolved (fixed in 19.4-2)
sid: resolved (fixed in 19.4-2)
trixie: resolved (fixed in 19.4-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-8632 cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py
bugzilla·2020-02-05·CVSS 5.5
CVE-2020-8632 [MEDIUM] CVE-2020-8632 cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py
CVE-2020-8632 cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
Upstream patch:
https://github.com/canonical/cloud-init/pull/189
https://github.com/canonical/cloud-init/commit/42788bf24a1a0a5421a2d00a7f59b59e38ba1a14
References:
https://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795
Discussion:
Created cloud-init tracking bugs for this issue:
Affects: epel-6 [bug 1798730]
Affects: fedora-all [bug 1798729]
---
As cc_set_passwords module could be used to set ssh password authentication as well, the Attack Vector is set to Network.
Confidentiality, Integri
Bugzilla
CVE-2020-8632 cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py [epel-6]
bugzilla·2020-02-05·CVSS 5.5
CVE-2020-8632 [MEDIUM] CVE-2020-8632 cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py [epel-6]
CVE-2020-8632 cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use
Bugzilla
CVE-2020-8632 cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py [fedora-all]
bugzilla·2020-02-05·CVSS 5.5
CVE-2020-8632 [MEDIUM] CVE-2020-8632 cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py [fedora-all]
CVE-2020-8632 cloud-init: Too short random password length in cc_set_password in config/cc_set_passwords.py [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: thi
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00042.htmlhttps://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795https://github.com/canonical/cloud-init/pull/189https://lists.debian.org/debian-lts-announce/2020/02/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00042.htmlhttps://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/1860795https://github.com/canonical/cloud-init/pull/189https://lists.debian.org/debian-lts-announce/2020/02/msg00021.html
2020-02-05
Published