CVE-2023-1786
published 2023-04-26CVE-2023-1786: Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly…
medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | cloud-init | < 23.1.2 | 23.1.2 |
| canonical | cloud-init | >= 0 < 23.2-1 | 23.2-1 |
| canonical | cloud-init | >= 0 < 23.2-1 | 23.2-1 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical_ltd | cloud-init | < 23.1.2 | 23.1.2 |
| debian | cloud-init | < cloud-init 23.2-1 (forky) | cloud-init 23.2-1 (forky) |
| fedoraproject | fedora | — | — |
| msrc | cbl2_cloud-init_22.4-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_cloud-init_21.4-3_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM