CVE-2021-3429
published 2023-04-19CVE-2021-3429: When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.22%
12.3th percentile
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | cloud-init | < 21.2 | 21.2 |
| canonical | cloud-init | >= 0 < 20.4.1-2 | 20.4.1-2 |
| canonical | cloud-init | >= 0 < 20.4.1-2 | 20.4.1-2 |
| canonical | cloud-init | >= 0 < 20.4.1-2 | 20.4.1-2 |
| canonical | cloud-init | >= 0 < 20.4.1-2 | 20.4.1-2 |
| canonical_ltd | cloud-init | < 21.2 | 21.2 |
| debian | cloud-init | < cloud-init 20.4.1-2 (bookworm) | cloud-init 20.4.1-2 (bookworm) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jj89-4799-j2qv: When instructing cloud-init to set a random password for a new user account, versions before 21
ghsa_unreviewed·2023-04-20
CVE-2021-3429 [MEDIUM] CWE-532 GHSA-jj89-4799-j2qv: When instructing cloud-init to set a random password for a new user account, versions before 21
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.
OSV
CVE-2021-3429: When instructing cloud-init to set a random password for a new user account, versions before 21
osv·2023-04-19·CVSS 5.5
CVE-2021-3429 [MEDIUM] CVE-2021-3429: When instructing cloud-init to set a random password for a new user account, versions before 21
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.
Red Hat
cloud-init: randomly generated passwords logged in clear-text to world-readable file
vendor_redhat·2021-03-23·CVSS 5.5
CVE-2021-3429 [MEDIUM] CWE-532 cloud-init: randomly generated passwords logged in clear-text to world-readable file
cloud-init: randomly generated passwords logged in clear-text to world-readable file
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.
A flaw was found in cloud-init. When a system is configured through cloud-init and the "Set Passwords" module is used with "chpasswd" directive and "RANDOM", the randomly generated password for the relative user is written in clear-text in a file readable by any existing user of the system. The highest threat from this vulnerability is to data confidentiality and it may allow a local attacker to log in as another user.
Statement: By default the randomly password g
Debian
CVE-2021-3429: cloud-init - When instructing cloud-init to set a random password for a new user account, ver...
vendor_debian·2021·CVSS 5.5
CVE-2021-3429 [MEDIUM] CVE-2021-3429: cloud-init - When instructing cloud-init to set a random password for a new user account, ver...
When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log file /var/log/cloud-init-output.log. This could allow a local user to log in as another user.
Scope: local
bookworm: resolved (fixed in 20.4.1-2)
bullseye: resolved (fixed in 20.4.1-2)
forky: resolved (fixed in 20.4.1-2)
sid: resolved (fixed in 20.4.1-2)
trixie: resolved (fixed in 20.4.1-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-19
Published