CVE-2022-2084
published 2023-04-19CVE-2022-2084: Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.24%
14.6th percentile
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | cloud-init | < 22.3 | 22.3 |
| canonical | cloud-init | >= 0 < 22.2-2 | 22.2-2 |
| canonical | cloud-init | >= 0 < 22.2-2 | 22.2-2 |
| canonical | cloud-init | >= 0 < 22.2-2 | 22.2-2 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical_ltd | cloud-init | < 23.0 | 23.0 |
| debian | cloud-init | < cloud-init 22.2-2 (bookworm) | cloud-init 22.2-2 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_cloud-init_21.4-4_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cloud-init: vulnerable to expose sensitive information
vendor_redhat·2023-04-20·CVSS 5.5
CVE-2022-2084 [MEDIUM] CWE-200 cloud-init: vulnerable to expose sensitive information
cloud-init: vulnerable to expose sensitive information
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.
A vulnerability was found in cloud-init. With this flaw, sensitive data could be exposed in world-readable cloud-init logs when schema failures are reported. This issue leak could include hashed passwords.
Package: cloud-init (Red Hat Enterprise Linux 6) - Not affected
Package: cloud-init (Red Hat Enterprise Linux 7) - Not affected
Package: cloud-init (Red Hat Enterprise Linux 8) - Not affected
Package: cloud-init (Red Hat Enterprise Linux 9) - Not affected
Microsoft
sensitive data exposure in cloud-init logs
vendor_msrc·2023-04-11·CVSS 5.5
CVE-2022-2084 [MEDIUM] CWE-532 sensitive data exposure in cloud-init logs
sensitive data exposure in cloud-init logs
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
canonical: canonical
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.micr
Ubuntu
cloud-init vulnerability
vendor_ubuntu·2022-06-29
CVE-2022-2084 cloud-init vulnerability
Title: cloud-init vulnerability
Summary: cloud-init could be made to expose sensitive information.
Mike Stroyan discovered that cloud-init could log password hashes when
reporting schema failures. An attacker with access to these logs could
potentially use this to gain user credentials.
Instructions: In general, a standard system update will make the necessary changes.
Please note that sensitive information may have been logged to remote
logging aggregators as well as to the system journal, and removal of
such information may be required. Similarly, cloud-init configurations
that log in non-default locations may also require the removal of
sensitive information.
Debian
CVE-2022-2084: cloud-init - Sensitive data could be exposed in world readable logs of cloud-init before vers...
vendor_debian·2022·CVSS 5.5
CVE-2022-2084 [MEDIUM] CVE-2022-2084: cloud-init - Sensitive data could be exposed in world readable logs of cloud-init before vers...
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.
Scope: local
bookworm: resolved (fixed in 22.2-2)
bullseye: resolved
forky: resolved (fixed in 22.2-2)
sid: resolved (fixed in 22.2-2)
trixie: resolved (fixed in 22.2-2)
GHSA
GHSA-w62x-qh57-5m94: Sensitive data could be exposed in world readable logs of cloud-init before version 22
ghsa_unreviewed·2023-04-20
CVE-2022-2084 [MEDIUM] CWE-532 GHSA-w62x-qh57-5m94: Sensitive data could be exposed in world readable logs of cloud-init before version 22
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.
OSV
CVE-2022-2084: Sensitive data could be exposed in world readable logs of cloud-init before version 22
osv·2023-04-19·CVSS 5.5
CVE-2022-2084 [MEDIUM] CVE-2022-2084: Sensitive data could be exposed in world readable logs of cloud-init before version 22
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include hashed passwords.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-19
Published