CVE-2023-1786
published 2023-04-26CVE-2023-1786: Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.26%
17.9th percentile
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | cloud-init | < 23.1.2 | 23.1.2 |
| canonical | cloud-init | >= 0 < 23.2-1 | 23.2-1 |
| canonical | cloud-init | >= 0 < 23.2-1 | 23.2-1 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical_ltd | cloud-init | < 23.1.2 | 23.1.2 |
| debian | cloud-init | < cloud-init 23.2-1 (forky) | cloud-init 23.2-1 (forky) |
| fedoraproject | fedora | — | — |
| msrc | cbl2_cloud-init_22.4-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_cloud-init_21.4-3_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2vcw-8vc6-xxfw: Sensitive data could be exposed in logs of cloud-init before version 23
ghsa_unreviewed·2023-04-27
CVE-2023-1786 [MEDIUM] CWE-532 GHSA-2vcw-8vc6-xxfw: Sensitive data could be exposed in logs of cloud-init before version 23
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
OSV
CVE-2023-1786: Sensitive data could be exposed in logs of cloud-init before version 23
osv·2023-04-26·CVSS 5.5
CVE-2023-1786 [MEDIUM] CVE-2023-1786: Sensitive data could be exposed in logs of cloud-init before version 23
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
Red Hat
cloud-init: sensitive data could be exposed in logs
vendor_redhat·2023-04-27·CVSS 5.5
CVE-2023-1786 [MEDIUM] CWE-200 cloud-init: sensitive data could be exposed in logs
cloud-init: sensitive data could be exposed in logs
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
A vulnerability was found in cloud-init. With this flaw, exposure of sensitive data is possible in world-readable cloud-init logs. This flaw allows an attacker to use this information to find hashed passwords and possibly escalate their privilege.
Package: cloud-init (Red Hat Enterprise Linux 6) - Out of support scope
Package: cloud-init (Red Hat Enterprise Linux 7) - Out of support scope
Ubuntu
Cloud-init vulnerability
vendor_ubuntu·2023-04-26
CVE-2023-1786 Cloud-init vulnerability
Title: Cloud-init vulnerability
Summary: cloud-init could write sensitive information to logs.
James Golovich discovered that sensitive data could be exposed in logs. An
attacker could use this information to find hashed passwords and possibly
escalate their privilege.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
sensitive data exposure in cloud-init logs
vendor_msrc·2023-04-11·CVSS 5.5
CVE-2023-1786 [MEDIUM] CWE-532 sensitive data exposure in cloud-init logs
sensitive data exposure in cloud-init logs
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
canonical: canonical
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.micr
Debian
CVE-2023-1786: cloud-init - Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An ...
vendor_debian·2023·CVSS 5.5
CVE-2023-1786 [MEDIUM] CVE-2023-1786: cloud-init - Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An ...
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 23.2-1)
sid: resolved (fixed in 23.2-1)
trixie: resolved (fixed in 23.2-1)
No detection rules found.
No public exploits indexed.
https://bugs.launchpad.net/cloud-init/+bug/2013967https://github.com/canonical/cloud-init/commit/a378b7e4f47375458651c0972e7cd813f6fe0a6bhttps://lists.fedoraproject.org/archives/list/[email protected]/message/ATBJSXPL2IOAD2LDQRKWPLIC7QXS44GZ/https://ubuntu.com/security/notices/USN-6042-1https://bugs.launchpad.net/cloud-init/+bug/2013967https://github.com/canonical/cloud-init/commit/a378b7e4f47375458651c0972e7cd813f6fe0a6bhttps://lists.fedoraproject.org/archives/list/[email protected]/message/ATBJSXPL2IOAD2LDQRKWPLIC7QXS44GZ/https://ubuntu.com/security/notices/USN-6042-1
2023-04-26
Published